[EKS] [eks-pod-identity]: Allow Namespace wildcards in Pod Identity Associations
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
Hi Team,
We are keen to utilise pod identities but a significant road block for our application is the need to create a pod identity association per namespace.
We have the same deployment per tenant but use a seprate namespace per tenant as per general security recommendations. The Service Account and Role used by the application is the same for each tenants deployment but given namespace needs to be specified exactly in the pod identity association, we require a pod identity association per tenant as well.
As our tenant namespaces can be easily represented by a simple regular expression it would be simpler to be able to add a single pod identity association using a namespace specified using a regular expression.
Look forward to your feedback and responses on this request. :-)
Tony
### Community Note
* Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
* If you are interested in working on this issue or have submitted a pull request, please leave a comment
**Tell us about your request**
What do you want us to build?
**Which service(s) is this request for?**
This could be Fargate, ECS, EKS, ECR
**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
What outcome are you trying to achieve, ultimately, and why is it hard/impossible to do right now? What is the impact of not having this problem solved? The more details you can provide, the better we'll be able to understand and solve the problem.
**Are you currently working around this issue?**
How are you currently solving this problem?
**Additional context**
Anything else we should know?
**Attachments**
If you think you might have additional information that you'd like to include via an attachment, please do - we'll take a look. (Remember to remove any personally-identifiable information.)
Contributor guide
Research direction
Start by reviewing the issue's EKS Pod Identity Association requirements and the stated tenant-namespace use case. Clarify whether namespace wildcards or regular expressions are intended, including their matching semantics and security implications. Done means one association can cover the described tenant namespaces without requiring a separate association for each namespace.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, kubernetes
- Domain
- cloud, infrastructure
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100