Skip to content

Commit 9333126

Browse files
authored
update recommended IAM policy template (#3068)
1 parent 381349d commit 9333126

File tree

3 files changed

+66
-0
lines changed

3 files changed

+66
-0
lines changed

docs/install/iam_policy.json

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -196,6 +196,28 @@
196196
}
197197
}
198198
},
199+
{
200+
"Effect": "Allow",
201+
"Action": [
202+
"elasticloadbalancing:AddTags"
203+
],
204+
"Resource": [
205+
"arn:aws:elasticloadbalancing:*:*:targetgroup/*/*",
206+
"arn:aws:elasticloadbalancing:*:*:loadbalancer/net/*/*",
207+
"arn:aws:elasticloadbalancing:*:*:loadbalancer/app/*/*"
208+
],
209+
"Condition": {
210+
"StringEquals": {
211+
"elasticloadbalancing:CreateAction": [
212+
"CreateTargetGroup",
213+
"CreateLoadBalancer"
214+
]
215+
},
216+
"Null": {
217+
"aws:RequestTag/elbv2.k8s.aws/cluster": "false"
218+
}
219+
}
220+
},
199221
{
200222
"Effect": "Allow",
201223
"Action": [

docs/install/iam_policy_cn.json

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -177,6 +177,28 @@
177177
"arn:aws-cn:elasticloadbalancing:*:*:listener-rule/app/*/*/*"
178178
]
179179
},
180+
{
181+
"Effect": "Allow",
182+
"Action": [
183+
"elasticloadbalancing:AddTags"
184+
],
185+
"Resource": [
186+
"arn:aws-cn:elasticloadbalancing:*:*:targetgroup/*/*",
187+
"arn:aws-cn:elasticloadbalancing:*:*:loadbalancer/net/*/*",
188+
"arn:aws-cn:elasticloadbalancing:*:*:loadbalancer/app/*/*"
189+
],
190+
"Condition": {
191+
"StringEquals": {
192+
"elasticloadbalancing:CreateAction": [
193+
"CreateTargetGroup",
194+
"CreateLoadBalancer"
195+
]
196+
},
197+
"Null": {
198+
"aws:RequestTag/elbv2.k8s.aws/cluster": "false"
199+
}
200+
}
201+
},
180202
{
181203
"Effect": "Allow",
182204
"Action": [

docs/install/iam_policy_us-gov.json

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -177,6 +177,28 @@
177177
"arn:aws-us-gov:elasticloadbalancing:*:*:listener-rule/app/*/*/*"
178178
]
179179
},
180+
{
181+
"Effect": "Allow",
182+
"Action": [
183+
"elasticloadbalancing:AddTags"
184+
],
185+
"Resource": [
186+
"arn:aws-us-gov:elasticloadbalancing:*:*:targetgroup/*/*",
187+
"arn:aws-us-gov:elasticloadbalancing:*:*:loadbalancer/net/*/*",
188+
"arn:aws-us-gov:elasticloadbalancing:*:*:loadbalancer/app/*/*"
189+
],
190+
"Condition": {
191+
"StringEquals": {
192+
"elasticloadbalancing:CreateAction": [
193+
"CreateTargetGroup",
194+
"CreateLoadBalancer"
195+
]
196+
},
197+
"Null": {
198+
"aws:RequestTag/elbv2.k8s.aws/cluster": "false"
199+
}
200+
}
201+
},
180202
{
181203
"Effect": "Allow",
182204
"Action": [

0 commit comments

Comments
 (0)