Skip to content

Commit d6ca4b7

Browse files
obezpalkoclaude
andauthored
feat: grant a default set of admin roles cluster access on every cluster (#82)
* feat: grant a default set of admin roles cluster access on every cluster Adds eks_default_admin_role_names (default admin-dply-terraform, comet-admin). The roles are looked up by name in the cluster's account, so the ARN carries the role's path (role/system/comet-admin) and a missing role fails at plan, not at CreateAccessEntry. They are merged with eks_admin_role_arns into one ARN-keyed set, so existing entries keep their keys and a principal listed in both gets one entry. Wrappers get the baseline on the version bump; set the variable to [] or a shorter list where a role doesn't exist (e.g. a cluster in another account). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: skip the default admin role lookup in CONFIG_MAP mode CONFIG_MAP clusters have no access entries, so the defaults can't apply there and the lookup would only add a way for the plan to fail. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
1 parent 67f51b8 commit d6ca4b7

4 files changed

Lines changed: 24 additions & 2 deletions

File tree

‎main.tf‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -274,6 +274,7 @@ module "comet_eks" {
274274
eks_authentication_mode = var.eks_authentication_mode
275275
eks_enable_cluster_creator_admin_permissions = var.eks_enable_cluster_creator_admin_permissions
276276
eks_admin_role_arns = var.eks_admin_role_arns
277+
eks_default_admin_role_names = var.eks_default_admin_role_names
277278
kms_key_administrators = var.eks_kms_key_administrators
278279
kms_key_users = var.eks_kms_key_users
279280
eks_mng_ami_type = var.eks_mng_ami_type

‎modules/comet_eks/main.tf‎

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -159,9 +159,11 @@ locals {
159159
} : {}
160160
)
161161

162-
# Build access entries for admin roles
162+
# Build access entries for admin roles: the fleet-wide defaults plus the caller's list,
163+
# keyed by ARN so order doesn't matter and a principal listed twice gets one entry.
164+
admin_role_arns = toset(concat([for r in data.aws_iam_role.default_admins : r.arn], var.eks_admin_role_arns))
163165
admin_access_entries = {
164-
for arn in var.eks_admin_role_arns : arn => {
166+
for arn in local.admin_role_arns : arn => {
165167
principal_arn = arn
166168
type = "STANDARD"
167169
policy_associations = {
@@ -1075,6 +1077,13 @@ module "cloudwatch_exporter_irsa_role" {
10751077
#### Karpenter Prerequisites ####
10761078
#########################################
10771079

1080+
# By name, so the ARN carries the role's path (comet-admin lives under /system/). Skipped in
1081+
# CONFIG_MAP mode, which has no access entries.
1082+
data "aws_iam_role" "default_admins" {
1083+
for_each = var.eks_authentication_mode == "CONFIG_MAP" ? toset([]) : toset(var.eks_default_admin_role_names)
1084+
name = each.value
1085+
}
1086+
10781087
data "aws_caller_identity" "current" {}
10791088

10801089
# Region consistency guard.

‎modules/comet_eks/variables.tf‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -81,6 +81,12 @@ variable "eks_admin_role_arns" {
8181
default = []
8282
}
8383

84+
variable "eks_default_admin_role_names" {
85+
description = "IAM role names in the cluster's account granted AmazonEKSClusterAdminPolicy on every cluster, in addition to eks_admin_role_arns. Looked up at plan, so a missing role fails the plan; set [] (or a shorter list) to opt out. Ignored when eks_authentication_mode is CONFIG_MAP."
86+
type = list(string)
87+
default = ["admin-dply-terraform", "comet-admin"]
88+
}
89+
8490
variable "kms_key_administrators" {
8591
description = "List of IAM ARNs (users/roles) that should have administrator access to the EKS KMS key. These principals can manage the key."
8692
type = list(string)

‎variables.tf‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -440,6 +440,12 @@ variable "eks_admin_role_arns" {
440440
default = []
441441
}
442442

443+
variable "eks_default_admin_role_names" {
444+
description = "IAM role names in the cluster's account granted AmazonEKSClusterAdminPolicy on every cluster, in addition to eks_admin_role_arns. Looked up at plan, so a missing role fails the plan; set [] (or a shorter list) to opt out. Ignored when eks_authentication_mode is CONFIG_MAP."
445+
type = list(string)
446+
default = ["admin-dply-terraform", "comet-admin"]
447+
}
448+
443449
variable "eks_kms_key_administrators" {
444450
description = "List of IAM ARNs (users/roles) that should have administrator access to the EKS KMS key. These principals can manage the key (update, delete, etc.)."
445451
type = list(string)

0 commit comments

Comments
 (0)