Support ServiceAccountToken in ecr-credential-provider#1155
Conversation
Extend ecr-credential-provider to support fine-grained access via kubernetes ServiceAccount tokens and STS's AssumeRoleWithWebIdentity. This allows users to avoid long-lived secrets in their pods/nodes and instead use a short-lived credential generated by kubernetes in order to access private ECR images.
|
This issue is currently awaiting triage. If cloud-provider-aws contributors determine this is a relevant issue, they will accept it by applying the The DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
Welcome @fletcherw! |
|
Hi @fletcherw. Thanks for your PR. I'm waiting for a kubernetes member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/ok-to-test |
|
/assign cartermckinnon |
|
This is great, thanks @fletcherw! /lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: cartermckinnon The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Extend ecr-credential-provider to support fine-grained access via kubernetes ServiceAccount tokens and STS's AssumeRoleWithWebIdentity.
This allows users to avoid long-lived secrets in their pods/nodes and instead use a short-lived credential generated by kubernetes in order to access private ECR images.
What type of PR is this?
/kind feature
What this PR does / why we need it: This PR
Which issue(s) this PR fixes:
Fixes #1147
Does this PR introduce a user-facing change?: