← All posts

Implementing Amazon EKS: From Zero to Deploy · Part 3 of 6

Implementing Amazon Elastic Kubernetes Service: From Zero to Deploy (Part 3/6)

Amazon Elastic Kubernetes Service (Amazon EKS) is a fully managed Kubernetes service on AWS. With it, customers such as Intel…

2 min read342 wordsSections: 1Code blocks: 1Apr 19, 2022

Keywords

Share
Comment
Implementing Amazon Elastic Kubernetes Service: From Zero to Deploy (Part 3/6)

Amazon Elastic Kubernetes Service (Amazon EKS) is a fully managed Kubernetes service on AWS. With it, customers such as Intel, Snap, Intuit, GoDaddy and many other companies run their most sensitive and mission-critical applications thanks to its security, reliability and scalability. In this series of posts we will see how to implement Amazon EKS from scratch all the way to deploying an application. The topics we will cover:

  • Part 1 — Configuring a cluster in EKS
  • Part 2 — Configuring node-groups in EKS
  • Part 3 — Configuring IAM users as Masters
  • Part 4 — Packaging from source code
  • Part 5 — Publishing a container image to ECR
  • Part 6 — Deploying to EKS from an image in ECR

Continuing our series, today we will configure IAM users as Masters of our Kubernetes environment.

Part 3 — Configuring IAM users as Masters

When you create an Amazon EKS cluster, the IAM entity role or user, such as a federated user, that creates the cluster is automatically granted system:masters permissions in the cluster’s RBAC configuration in the control plane.

This IAM entity does not appear in the ConfigMap or in any other visible configuration, so make sure you keep track of which IAM entity originally created the cluster. To grant additional AWS users or roles the ability to interact with your cluster, you must edit the aws-auth ConfigMap in Kubernetes.

For more information on how Amazon EKS works with IAM, see https://docs.aws.amazon.com/pt_br/eks/latest/userguide/security_iam_service-with-iam.html.

CONFIGURING IAM USERS AS MASTERS

  • Edit the configmap to add the permission for the new user:
  • kubectl edit -n kube-system configmap/aws-auth
apiVersion: v1
data:
  mapaRoles: |
  — rolearn: <node instance role ARN>
  username: system:node:{{EC2PrivateDNSName}}
groups:
  — system:bootstrappers
  — system:nodes
  mapUsers: |
  — userarn: arn:aws:iam12345789012:user/Alice
  username: alice
groups:
  — system:masters
  kind: ConfigMap
  metadata: …
  • Run kubeconfig to update the profile;
  • aws eks update-kubeconfig — name EKSDeepDive
  • kubectl get nodes

In our next post, we will talk about how to package our application from source code.

See you then! =)

Comments

Every comment is moderated before it appears here. Nothing is published automatically.

Loading…