bottlerocket-os / bottlerocket-os/bottlerocket-test-system

minimal set of iam permissions

Open
#417 0 comments 0 reactions 0 assignees View on GitHub
documentation enhancement help wanted resource-agent
Dominant language
Rust
Stars
18
Forks
27
PR merge metrics
No merged PRs in 30d

Description

We need to come up with the minimal set of IAM permissions that are required to run our test and resource agents on EC2/EKS nodes.
Note that in #379 we want to give EKS and ECS providers a way to create clusters with create role or create instance profile permissions. So our minimal set of permissions should not include those (possibly with an option to add those in for the local developer workflow use case).

Contributor guide

Open the contributing guide

Research direction

Start by inventorying the IAM permissions required by the test and resource agents when running on EC2 and EKS nodes. Review issue #379 to exclude permissions for creating roles or instance profiles, and determine whether those belong behind an optional local-developer workflow setting. Done means the minimal permission set and any optional additions are clearly defined.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
cloud, infrastructure, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.