UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects

833 gitlab iam role

Merged Cassie Souza requested to merge 833-gitlab-iam-role into main
All threads resolved!

This MR allows us to check if an AWS IAM Profile is being used for object storage. If so, then it will modify the egress-kube-api network policy to allow access to the AWS metadata endpoint

Partially closes https://repo1.dso.mil/platform-one/big-bang/bigbang/-/issues/833

Merge request reports

Merge request pipeline #551030 passed with warnings

Merge request pipeline passed with warnings for 3e793c09

Merged by Ryan GarciaRyan Garcia 3 years ago (Nov 1, 2021 10:45pm UTC)

Loading

Pipeline #551152 passed with warnings

Pipeline passed with warnings for bddbdd5c on main

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
  • This will technically work but i want to get Ryan's opinion on this. And maybe Micah's opinion.

  • Cassie Souza added 1 commit

    added 1 commit

    Compare with previous version

  • Cassie Souza resolved all threads

    resolved all threads

    • Resolved by Ryan Garcia

      In addition @cassiesouza we will need to add a new NetworkPolicy template eg egress-metadata.yaml with explicit egress to 169.254.169.254/32 when use_iam_profile is true and we will need multiple copies of the networkPolicy resource YAML to apply to all pods that will need to be reaching out, eg: task-runner, webservice, sidekiq, etc.

  • Ryan Garcia added statusdoing label and removed statusreview label

    added statusdoing label and removed statusreview label

  • Ryan Garcia added 7 commits

    added 7 commits

    Compare with previous version

  • Ryan Garcia added 1 commit

    added 1 commit

    • e6b47ee3 - Readme and chart update, also templating on api-egress

    Compare with previous version

  • Ryan Garcia added 1 commit

    added 1 commit

    • b2d59388 - Adding AWS metadata allow NPs for 4 pods

    Compare with previous version

  • Ryan Garcia resolved all threads

    resolved all threads

  • Ryan Garcia added statusreview label and removed statusdoing label

    added statusreview label and removed statusdoing label

  • Cassie Souza added 1 commit

    added 1 commit

    Compare with previous version

  • Ryan Garcia added 1 commit

    added 1 commit

    • 3e793c09 - Testing blocking all to aws metadata when 0.0.0.0 specified

    Compare with previous version

  • Ryan Garcia approved this merge request

    approved this merge request

  • merged

  • Ryan Garcia mentioned in commit bddbdd5c

    mentioned in commit bddbdd5c

  • Please register or sign in to reply
    Loading