Skip to content

feat: configurable AWS Load Balancer Controller IRSA namespace/SA subjects - #62

Merged
obezpalko merged 2 commits into
mainfrom
feat/alb-irsa-namespace-subjects
Aug 11, 2026
Merged

obezpalko merged 2 commits into
mainfrom
feat/alb-irsa-namespace-subjects

Conversation

@obezpalko

@obezpalko obezpalko commented Aug 11, 2026 •

Copy link
Copy Markdown

User description

What

Adds aws_load_balancer_controller_namespace_service_accounts (list of <ns>:<sa> OIDC subjects) to the ALB controller IRSA role, defaulting to the current ["kube-system:aws-load-balancer-controller"] (backward-compatible). Replaces the previously hardcoded subject in modules/comet_eks/main.tf. Threaded root → comet_eks, mirroring the external-secrets change (#60).

Why

Prerequisite for folding the AWS Load Balancer Controller into the comet-infra umbrella (comet-system namespace). The IRSA trust is a StringEquals exact-match on the SA subject, so moving the controller's SA breaks AWS auth unless the trust allows the new subject.

During migration the caller lists both subjects for a zero-gap cutover. Note: the umbrella runs the controller with default (release-prefixed) naming — so the new SA is comet-infra-aws-load-balancer-controller (chosen over fullnameOverride to avoid a ClusterRole name-collision with the standalone app during the overlap). The dual-subject list is therefore:

aws_load_balancer_controller_namespace_service_accounts = [
  "kube-system:aws-load-balancer-controller",                # standalone app (current)
  "comet-system:comet-infra-aws-load-balancer-controller",   # umbrella (new, release-prefixed SA)
]

then a follow-up trims to just the umbrella subject.

Impact

Default unchanged → no diff for any existing cluster until a caller sets the new variable. Suggested release: v5.4.0.

Note: main.tf shows alignment churn from terraform fmt (the long variable name widened the = alignment of the module.comet_eks block). The only functional change is the single new pass-through line — confirm with git diff -w.

🤖 Generated with Claude Code


Generated description

Below is a concise technical summary of the changes proposed in this PR:
Configure AWS Load Balancer Controller IRSA trust through aws_load_balancer_controller_namespace_service_accounts, passing it from the root module into comet_eks while preserving the existing default. Document the required ServiceAccount subject and validate namespace/name entries to support zero-gap migration to the comet-infra umbrella.

TopicDetails
Configurable IRSA trust Allow callers to configure exact OIDC-trusted ServiceAccount subjects for the AWS Load Balancer Controller, including simultaneous standalone and umbrella subjects during migration while retaining backward compatibility.
Modified files (4)
  • main.tf
  • modules/comet_eks/main.tf
  • modules/comet_eks/variables.tf
  • variables.tf
Latest Contributors(2)
UserCommitDate
alexb@comet.comfix(baz): validate IRS...August 11, 2026
CRThazeMerge pull request #52...July 29, 2026
IRSA usage guidance Clarify that the controller ServiceAccount must match the configured IRSA subject and explain the default and umbrella naming expectations.
Modified files (2)
  • modules/comet_eks/outputs.tf
  • outputs.tf
Latest Contributors(2)
UserCommitDate
alexb@comet.comfix(baz): validate IRS...August 11, 2026
jms200v1.17.1 hotfix: escape...June 02, 2026
Review this PR on Baz | Customize your next review

…jects

Mirrors the external-secrets change: adds
`aws_load_balancer_controller_namespace_service_accounts` (default keeps the current
["kube-system:aws-load-balancer-controller"], backward-compatible) and wires it into
the ALB controller IRSA role's OIDC trust in place of the hardcoded subject. Threaded
root -> comet_eks.

Enables folding the AWS Load Balancer Controller into the comet-infra umbrella
(comet-system ns): during migration the caller lists BOTH subjects
["kube-system:aws-load-balancer-controller", "comet-system:aws-load-balancer-controller"]
for a zero-gap cutover, then trims to just comet-system.

(main.tf shows alignment churn from terraform fmt widening the block; the only
functional change is the one new pass-through line — verify with `git diff -w`.)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@obezpalko
obezpalko requested a review from a team as a code owner August 11, 2026 06:17
Comment thread variables.tf
baz review on #62 (2 medium findings):

1. Validation: the *_namespace_service_accounts vars accepted arbitrary strings.
   The upstream module prepends "system:serviceaccount:" and matches with
   StringEquals, so a malformed or wildcard entry silently yields an IRSA trust the
   ServiceAccount can never assume. Add element validation ("<namespace>:<serviceaccount>"
   — exactly one colon, each part a DNS-1123 label, no wildcards) to BOTH the ALB and
   external-secrets vars at BOTH the root and child (comet_eks) boundaries. Tested: the
   regex accepts kube-system:aws-load-balancer-controller /
   comet-system:comet-infra-aws-load-balancer-controller / external-secrets:external-secrets
   and rejects wildcard/no-colon/extra-colon/empty/uppercase/underscore.

2. Stale docs: the ALB IRSA outputs (root + comet_eks) and the header comment hardcoded
   "annotate kube-system/aws-load-balancer-controller", which is wrong once the subject is
   configurable (and when folded into comet-infra the SA lives in comet-system). Reword to
   point at aws_load_balancer_controller_namespace_service_accounts as the source of truth.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@obezpalko obezpalko self-assigned this Aug 11, 2026
@obezpalko
obezpalko merged commit 8addd17 into main Aug 11, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant