aws / aws/containers-roadmap

[EKS] [request]: Ability to create custom EKS access policies

Open
#2,411 9 comments 67 reactions 0 assignees View on GitHub
EKS Proposed
Dominant language
Shell
Stars
5.4k
Forks
334
PR merge metrics
No merged PRs in 30d

Description

**Tell us about your request**
We have recently started using the EKS access entries for allowing IAM entities access the EKS cluster control plane. But at the moment there are only few predefined access policies we can use.
We would like to have the ability to create custom access policies.

**Which service(s) is this request for?**
EKS

**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
We are a platform team building EKS clusters for application teams. When we provision an EKS cluster, we would like to provide controlled access to (beyond what's available in predefined access policies, eg: to a specific namespace and to a specific set of resources) to the dev teams using the cluster at the time of provisioning the clusters.
The current solution we use have the necessary configurations in few places and done in different stages. It would be great if we can provision dev team access while provisioning the clusters.

**Are you currently working around this issue?**
How are you currently solving this problem?
At the moment we are solving this problem by creating K8s RBAC resources and assigning k8s group names to IAM entities using access entries.

Contributor guide

Open the contributing guide

Research direction

The request concerns EKS access entries, predefined access policies, Kubernetes RBAC resources, and IAM entities, but it names no repository files, tests, or implementation entry points. Start by determining whether this roadmap repository contains an implementation area for EKS access policies; done would require a defined way to provision custom policies for specific namespaces and resources.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, kubernetes
Domain
authorization, cloud, infrastructure, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.