Skip to content

Commit

Permalink
Merge pull request #6655 from Himangini/update-iam-policy
Browse files Browse the repository at this point in the history
Updated IAM policy statement for loadbalancer controller
  • Loading branch information
Himangini committed May 31, 2023
2 parents dad16d7 + 3d95c5a commit 52d3eed
Showing 1 changed file with 22 additions and 0 deletions.
22 changes: 22 additions & 0 deletions pkg/cfn/builder/statement.go
Original file line number Diff line number Diff line change
Expand Up @@ -84,6 +84,28 @@ func loadBalancerControllerStatements() []cft.MapOfInterfaces {
"elasticloadbalancing:RemoveTags",
},
},
{
"Effect": effectAllow,
"Action": []string{
"elasticloadbalancing:AddTags",
},
"Resource": []*gfnt.Value{
addARNPartitionPrefix("elasticloadbalancing:*:*:targetgroup/*/*"),
addARNPartitionPrefix("elasticloadbalancing:*:*:loadbalancer/net/*/*"),
addARNPartitionPrefix("elasticloadbalancing:*:*:loadbalancer/app/*/*"),
},
"Condition": map[string]interface{}{
"StringEquals": map[string]interface{}{
"elasticloadbalancing:CreateAction": []string{
"CreateTargetGroup",
"CreateLoadBalancer",
},
},
"Null": map[string]string{
"aws:RequestTag/elbv2.k8s.aws/cluster": "false",
},
},
},
{
"Effect": effectAllow,
"Resource": resourceAll,
Expand Down

0 comments on commit 52d3eed

Please sign in to comment.