Skip to content

Commit

Permalink
Merge pull request #372 from cookpad/coord-e/use-inline-policy-for-v1…
Browse files Browse the repository at this point in the history
…beta

Use inline policy for v1beta to avoid resource recreation
  • Loading branch information
coord-e authored Nov 6, 2024
2 parents 667a032 + a694019 commit 6d48a60
Showing 1 changed file with 8 additions and 8 deletions.
16 changes: 8 additions & 8 deletions modules/karpenter/controller_iam.tf
Original file line number Diff line number Diff line change
Expand Up @@ -28,18 +28,18 @@ data "aws_iam_policy_document" "karpenter_controller_assume_role_policy" {
}
}

resource "aws_iam_role_policy_attachment" "karpenter_controller_v1_beta" {
count = var.v1beta ? 1 : 0
role = aws_iam_role.karpenter_controller.id
policy_arn = aws_iam_policy.karpenter_controller_v1_beta[0].arn
}

resource "aws_iam_policy" "karpenter_controller_v1_beta" {
resource "aws_iam_role_policy" "karpenter_controller_v1_beta" {
count = var.v1beta ? 1 : 0
name = "${var.cluster_config.iam_policy_name_prefix}KarpenterController-v1beta-${var.cluster_config.name}"
name = "KarpenterController-v1beta"
role = aws_iam_role.karpenter_controller.id
policy = data.aws_iam_policy_document.karpenter_controller_v1_beta.json
}

moved {
from = aws_iam_role_policy.karpenter_controller_v1_beta
to = aws_iam_role_policy.karpenter_controller_v1_beta[0]
}

data "aws_iam_policy_document" "karpenter_controller_v1_beta" {
statement {
sid = "AllowScopedEC2InstanceAccessActions"
Expand Down

0 comments on commit 6d48a60

Please sign in to comment.