Skip to content

Commit f49407f

Browse files
mtulioameukam
authored andcommitted
feat/ccm-aws: added permissions to RW*TargetGroupAttributes
Added permission to read and write/modify Target Group Attributes on clusters of cloud-provider-aws (CCM) project. The modify permission is conditional for targget clusters. This permission is required to be able to test the new requirement, modify target group attributes, through e2e CI clusters. More information: kubernetes/cloud-provider-aws#1214 Example of CI job without this permission: https://prow.k8s.io/view/gs/kubernetes-ci-logs/pr-logs/pull/cloud-provider-aws/1214/pull-cloud-provider-aws-e2e/1948477553773645824 Signed-off-by: Arnaud Meukam <ameukam@gmail.com>
1 parent 963c6bc commit f49407f

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

pkg/model/iam/iam_builder.go

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -879,6 +879,7 @@ func AddCCMPermissions(p *Policy, cloudRoutes bool) {
879879
"elasticloadbalancing:DescribeListeners",
880880
"elasticloadbalancing:DescribeLoadBalancerPolicies",
881881
"elasticloadbalancing:DescribeTargetGroups",
882+
"elasticloadbalancing:DescribeTargetGroupAttributes",
882883
"elasticloadbalancing:DescribeTargetHealth",
883884
"iam:CreateServiceLinkedRole",
884885
"kms:DescribeKey",
@@ -906,6 +907,7 @@ func AddCCMPermissions(p *Policy, cloudRoutes bool) {
906907
"elasticloadbalancing:DeleteTargetGroup",
907908
"elasticloadbalancing:ModifyListener",
908909
"elasticloadbalancing:ModifyTargetGroup",
910+
"elasticloadbalancing:ModifyTargetGroupAttributes",
909911
"elasticloadbalancing:RegisterTargets",
910912
"elasticloadbalancing:DeregisterTargets",
911913
"elasticloadbalancing:SetLoadBalancerPoliciesOfListener",

0 commit comments

Comments
 (0)