{"repo":"fanicia/kind-aws-irsa-example","free":true,"listed":false,"github":"https://github.com/fanicia/kind-aws-irsa-example","clone":"git clone https://github.com/fanicia/kind-aws-irsa-example.git","description":"This repository shows off how you can use IAM Roles for Service Accounts (IRSA) in self-hosted Kubernetes clusters","language":"Shell","stars":11,"topics":[],"license":"Apache-2.0","category":"self-hosted-apps","readme_excerpt":"README Introduction This repository shows off how you can use IAM Roles for Service Accounts (IRSA) in self-hosted Kubernetes clusters. As this is a demo-type repository, I just spin up a Kind cluster here, but the technique should work for production-level clusters just as well. Furthermore, to avoid gold-plating this project out of the gate, I have included a few hacks to get things working. How to run it? Simply run the full-setup.sh script, and you should get a kind cluster with a Job s3-echoer that authenticates to your AWS Account and places a file in an output-bucket as a demo. The script automatically waits for all dependencies (cert-manager, pod-identity-webhook) to be ready before proceeding. Each run automatically generates a unique UUID-based identifier, allowing multiple isolated stacks to run simultaneously. If you want to use a specific identifier (for reproducibility or named stacks), provide it as an argument: Configuration AWS Region By default, all AWS resources (S3 buckets, IAM roles, OIDC providers) are created in eu-west-1 . You can override this by setting the AWS DEFAULT REGION environment variable: The region configuration affects: - S3 bucket locations for OIDC discovery and demo output - OIDC provider endpoint URLs - IAM resource creation - Kubernetes pod environment variables Note: Make sure to use the same region when running the teardown script, or specify the suffix of the stack you want to delete. Prerequisites To run the script you need to hav","default_branch":null,"files":null,"tree":[],"storefront":"/r/fanicia","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/fanicia/kind-aws-irsa-example/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}