Skip to content

Commit

Permalink
Updating runner and ml nodes to use scoped permission (#17)
Browse files Browse the repository at this point in the history
  • Loading branch information
jeeva-duplo authored Jun 24, 2024
1 parent 9832677 commit a30e815
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions terraform/modules/galileo-eks/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -165,7 +165,7 @@ module "eks_galileo" {
AmazonEKSWorkerNodePolicy = "arn:aws:iam::aws:policy/AmazonEKSWorkerNodePolicy",
AmazonEC2ContainerRegistryReadOnly = "arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly",
ClusterAutoscaler = "arn:aws:iam::${data.aws_caller_identity.current.account_id}:policy/ClusterAutoscaler_${var.cluster_name}",
AmazonS3FullAccess = "arn:aws:iam::aws:policy/AmazonS3FullAccess",
GalileoS3BucketAccess = aws_iam_policy.galileo_s3_permission.arn,
AmazonSSMManagedInstanceCore = "arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore",
CloudWatchAgentServerPolicy = "arn:aws:iam::aws:policy/CloudWatchAgentServerPolicy",
AmazonEBSCSIDriverPolicy = "arn:aws:iam::aws:policy/service-role/AmazonEBSCSIDriverPolicy",
Expand Down Expand Up @@ -202,7 +202,7 @@ module "eks_galileo" {
AmazonEKSWorkerNodePolicy = "arn:aws:iam::aws:policy/AmazonEKSWorkerNodePolicy",
AmazonEC2ContainerRegistryReadOnly = "arn:aws:iam::aws:policy/AmazonEC2ContainerRegistryReadOnly",
ClusterAutoscaler = "arn:aws:iam::${data.aws_caller_identity.current.account_id}:policy/ClusterAutoscaler_${var.cluster_name}",
AmazonS3FullAccess = "arn:aws:iam::aws:policy/AmazonS3FullAccess",
GalileoS3BucketAccess = aws_iam_policy.galileo_s3_permission.arn,
AmazonSSMManagedInstanceCore = "arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore",
CloudWatchAgentServerPolicy = "arn:aws:iam::aws:policy/CloudWatchAgentServerPolicy",
AmazonEBSCSIDriverPolicy = "arn:aws:iam::aws:policy/service-role/AmazonEBSCSIDriverPolicy",
Expand Down

0 comments on commit a30e815

Please sign in to comment.