Skip to content

Commit dea6c44

Browse files
joey100Shuipingbryantbiggs
authored
fix: Use dynamic partition data source to determine DNS suffix for Karpenter EC2 pass role permission (#3193)
* fix karpenter iam passrole to ec2 api bug, to support aws cn * fix: Use dyanmic partition value for DNS suffix --------- Co-authored-by: Shuiping <[email protected]> Co-authored-by: Bryant Biggs <[email protected]>
1 parent 4abc779 commit dea6c44

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

modules/karpenter/policy.tf

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -195,7 +195,7 @@ data "aws_iam_policy_document" "v033" {
195195
condition {
196196
test = "StringEquals"
197197
variable = "iam:PassedToService"
198-
values = ["ec2.amazonaws.com"]
198+
values = ["ec2.${local.dns_suffix}"]
199199
}
200200
}
201201

@@ -584,7 +584,7 @@ data "aws_iam_policy_document" "v1" {
584584
condition {
585585
test = "StringEquals"
586586
variable = "iam:PassedToService"
587-
values = ["ec2.amazonaws.com"]
587+
values = ["ec2.${local.dns_suffix}"]
588588
}
589589
}
590590

0 commit comments

Comments
 (0)