jetstack / jetstack/version-checker

does not seem to support kube2iam for ECR access

Offen
#66 3 Kommentare 4 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
enhancement help wanted
Vorherrschende Sprache
Go
Sterne
778
Forks
82
Ø Merge
2 Min.
Gemergte PRs (30 T.)
3

Beschreibung

Hello,

I have a K8S cluster deployed in AWS with kubeadm.
Some of my images comes from the ECR of the K8S AWS account and I wanted to use kube2iam annotation on version-checker pod to allow it to check for image tags but it does not seem to work :

version-checker pod :
```
apiVersion: v1
kind: Pod
metadata:
annotations:
enable.version-checker.io/version-checker: "true"
iam.amazonaws.com/role: ecr-read-profile
[...]
```

version-checker logs :
```
time="2020-12-07T14:47:39Z" level=error msg="error syncing 'checkoutservice-78b576896d-9pk6z/microdemo': failed to sync pod checkoutservice-78b576896d-9pk6z/microdemo: failed to check container image \"server\": failed to get tags from remote registry for \".dkr.ecr.eu-central-1.amazonaws.com/google-samples/microservices-demo/checkoutservice\": failed to describe images: EmptyStaticCreds: static credentials are empty, requeuing" module=controller
```

Does the ECR authent only work with static credentials ?
Would it be possible to support kube2iam to avoid giving the pod static key and password ?
Thanks

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start by reviewing the version-checker pod manifest and the logged ECR authentication failure, then trace how ECR credentials are obtained for image-tag checks. Compare that flow with the kube2iam role annotation shown in the issue. Done means the pod can check ECR tags using kube2iam-provided credentials instead of static keys, with the behavior verified in an appropriate test or reproduction.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
aws, docker, go, kubernetes
Bereich
authentication, cloud, devops
Issue-Typ
Feature
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
28/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.