-
Notifications
You must be signed in to change notification settings - Fork 707
Add Private CA Addon #1020
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Add Private CA Addon #1020
Changes from 1 commit
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -78,6 +78,10 @@ You can use any of the following Amazon EKS add-ons. | |
|<<add-ons-pod-id>> | ||
|EC2, EKS Hybrid Nodes | ||
|
||
|Enable users to obtain certificates from AWS Private Certificate Authority (AWS Private CA) for Kubernetes | ||
|<<add-ons-aws-privateca-connector>> | ||
|EC2, EKS Auto Mode | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Missing Fargate and Hybrid here |
||
|
||
|=== | ||
|
||
[#add-ons-vpc-cni] | ||
|
@@ -483,6 +487,29 @@ eksctl create iamserviceaccount \ | |
|
||
For more information, see link:AmazonCloudWatch/latest/monitoring/install-CloudWatch-Observability-EKS-addon.html[Install the CloudWatch agent,type="documentation"]. | ||
|
||
[#add-ons-aws-privateca-connector] | ||
== AWS Private CA Connector for Kubernetes | ||
|
||
[abstract] | ||
-- | ||
Learn about the AWS Private CA Connector for Kubernetes Amazon EKS add-on. | ||
-- | ||
|
||
The AWS Private CA Connector for Kubernetes is an add-on for cert-manager that enables users to obtain Certificates from AWS Private Certificate Authority (AWS Private CA). | ||
|
||
* The Amazon EKS add-on name is `aws-privateca-connector-for-kubernetes`. | ||
* The add-on namespace is `aws-privateca-issuer`. | ||
|
||
[#add-ons-aws-privateca-connector-iam-permissions] | ||
=== Required IAM permissions | ||
|
||
This add-on uses the IAM roles for service accounts capability of Amazon EKS. For more information, see <<iam-roles-for-service-accounts>>. | ||
geoffcline marked this conversation as resolved.
Show resolved
Hide resolved
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. we support pod identity too. |
||
|
||
[#add-ons-aws-privateca-connector-information] | ||
=== Additional information | ||
|
||
geoffcline marked this conversation as resolved.
Show resolved
Hide resolved
|
||
For more information, see the https://github.com/cert-manager/aws-privateca-issuer[AWS Private CA Issuer for Kubernetes GitHub repository]. | ||
geoffcline marked this conversation as resolved.
Show resolved
Hide resolved
geoffcline marked this conversation as resolved.
Show resolved
Hide resolved
|
||
|
||
[#add-ons-pod-id] | ||
== EKS Pod Identity Agent | ||
|
||
|
@@ -508,4 +535,4 @@ This add-on users permissions from the <<create-node-role,Amazon EKS node IAM ro | |
[#add-ons-pod-id-update-information] | ||
=== Update information | ||
|
||
You can only update one minor version at a time. For example, if your current version is `1.28.x-eksbuild.y` and you want to update to `1.30.x-eksbuild.y`, then you must update your current version to `1.29.x-eksbuild.y` and then update it again to `1.30.x-eksbuild.y`. For more information about updating the add-on, see <<vpc-add-on-update>>. | ||
You can only update one minor version at a time. For example, if your current version is `1.28.x-eksbuild.y` and you want to update to `1.30.x-eksbuild.y`, then you must update your current version to `1.29.x-eksbuild.y` and then update it again to `1.30.x-eksbuild.y`. For more information about updating the add-on, see <<vpc-add-on-update>>. |
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Enable cert-manager to issue X.509 certificates from AWS Private CA. Requires cert-manager.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
this is what we have in the console.