You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 9b0382f
Browse filesBrowse the repository at this point in the historyBrowse files
feat(comet_eks): byo_s3_irsa_roles — customer bring-your-own-S3 IAM (DND-1423) (#48)
* feat(comet_eks): add byo_s3_irsa_roles for customer bring-your-own-S3 (DND-1423)
Add a reusable, opt-in `byo_s3_irsa_roles` map that provisions the IAM that
accompanies a customer-supplied S3 bucket: one IRSA role + a scoped
customer-managed policy + attachment per map entry. The trusted Kubernetes
ServiceAccounts (the IRSA :sub condition) are an explicit input, so the trust
list is codified and reviewable in PRs.
This generalizes the BYO-S3 access role that was previously created out-of-band
during onboarding (e.g. Zoox's ZooxS3Access), whose invisible trust list let a
missing ServiceAccount silently break ClickHouse remote backups for >=7 days
(DND-1413). It follows the existing Loki IRSA triplet exactly and reuses the
upstream iam-role-for-service-accounts-eks module to build the web-identity
trust.
- Permissions are scoped to the supplied bucket ARN(s) by default (not
s3:::*), so the feature is least-privilege from day one.
- role_name_override / policy_name_override let an existing out-of-band role or
policy be adopted in place via `terraform import` (stable ARN -> IRSA
annotations keep working) instead of being recreated.
- Empty map default -> no effect on any existing consumer.
New MINOR (new feature family): release as v1.21.0.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(comet_eks): validate byo_s3_irsa_roles inputs at plan time (DND-1423 PR review)
Address Baz review on PR #48. The variable only length-checked its lists, so
malformed inputs passed `terraform validate` and failed at apply (or silently
produced broken IAM/IRSA):
- bucket_arns: require an exact `arn:aws:s3:::<bucket>` per entry — reject
wildcards (`arn:aws:s3:::*`, which would reintroduce the over-broad grant this
feature exists to remove) and trailing `/*`/object keys (main.tf already
appends `/*`, so a trailing glob yields `<bucket>/*/*`).
- namespace_service_accounts: require `<namespace>:<sa-name>` — a malformed
subject silently produces a trust condition no pod can satisfy.
- policy_name_override: add IAM policy-name validation (1-128 chars) for parity
with the existing role_name_override check.
Verified the regexes accept the intended Zoox values and reject the bad cases;
`terraform validate` passes.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
# DND-1423: Bring-your-own-S3 IRSA roles. When a customer supplies their own S3
416
+
# bucket (e.g. ClickHouse remote backups), the pods that touch it need an IAM
417
+
# role assumable via IRSA and a policy scoped to that bucket. Each map entry
418
+
# provisions one such role + customer-managed policy + attachment. This
419
+
# generalizes roles previously created out-of-band during BYO-S3 onboarding
420
+
# (e.g. Zoox's ZooxS3Access) so the trusted ServiceAccounts are codified and
421
+
# reviewable. The map key is a short logical name used in resource naming.
422
+
variable"byo_s3_irsa_roles" {
423
+
description="Map of bring-your-own-S3 IRSA roles. Each entry grants the listed Kubernetes ServiceAccounts (via IRSA web-identity) scoped access to a customer-supplied S3 bucket. Empty by default (feature off)."
424
+
type=map(object({
425
+
# ARNs of the customer-supplied bucket(s). Permissions are scoped to these
426
+
# (bucket + bucket/*) - do NOT pass arn:aws:s3:::* here.
427
+
bucket_arns =list(string)
428
+
# ServiceAccounts allowed to assume the role, as "<namespace>:<sa-name>".
error_message="byo_s3_irsa_roles[*].bucket_arns entries must be an exact bucket ARN 'arn:aws:s3:::<bucket>' (no wildcards, no trailing /*, no object key)."
457
+
}
458
+
# Each entry must be "<namespace>:<sa-name>" (the format the upstream IRSA
459
+
# module expands into system:serviceaccount:<ns>:<sa>). A malformed subject
460
+
# silently produces a trust condition no pod can satisfy.
error_message="byo_s3_irsa_roles[*].namespace_service_accounts entries must be '<namespace>:<sa-name>' (both non-empty, lowercase DNS-safe, exactly one colon)."
# DND-1423: Bring-your-own-S3 IRSA roles (see modules/comet_eks/variables.tf for
81
+
# the full schema). Empty by default => feature off. Set an entry per customer
82
+
# BYO bucket that pods must reach via IRSA (e.g. ClickHouse remote backups).
83
+
variable"byo_s3_irsa_roles" {
84
+
description="Map of bring-your-own-S3 IRSA roles. Each entry grants listed Kubernetes ServiceAccounts (via IRSA) scoped access to a customer-supplied S3 bucket. Empty by default."
0 commit comments