bottlerocket-os / bottlerocket-os/bottlerocket-test-system
minimal set of iam permissions
- Dominant language
- Rust
- Stars
- 18
- Forks
- 27
- PR merge metrics
- No merged PRs in 30d
Description
We need to come up with the minimal set of IAM permissions that are required to run our test and resource agents on EC2/EKS nodes.
Note that in #379 we want to give EKS and ECS providers a way to create clusters with create role or create instance profile permissions. So our minimal set of permissions should not include those (possibly with an option to add those in for the local developer workflow use case).
Contributor guide
Research direction
Start by inventorying the IAM permissions required by the test and resource agents when running on EC2 and EKS nodes. Review issue #379 to exclude permissions for creating roles or instance profiles, and determine whether those belong behind an optional local-developer workflow setting. Done means the minimal permission set and any optional additions are clearly defined.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws
- Domain
- cloud, infrastructure, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100