Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add IRSA (workload identity) support for AWS cloud provider #7618

Closed
1 task
Tracked by #43
Reshrahim opened this issue May 20, 2024 · 2 comments · Fixed by #7708, #7739, #7738 or #7757
Closed
1 task
Tracked by #43

Add IRSA (workload identity) support for AWS cloud provider #7618

Reshrahim opened this issue May 20, 2024 · 2 comments · Fixed by #7708, #7739, #7738 or #7757
Labels
feature This issue describes a feature request in Radius triaged This issue has been reviewed and triaged

Comments

@Reshrahim
Copy link
Contributor

Reshrahim commented May 20, 2024

Overview of feature request

Current State
Today when you register the AWS provider, it AWS Access Key ID and the AWS Secret Access Key of IAM role. This is how UCP connects to AWS in order to deploy Azure resources.

Desired State
We should also support IAM roles for service accounts which is the equivalent of workload identity for AWS

Acceptance criteria

  1. Setup IRSA on their cluster
  2. Register their AWS provider with the IAM role
  3. Deploy AWS resources

Additional context

No response

Would you like to support us?

  • Yes, I would like to support you

AB#12397

@Reshrahim Reshrahim added the feature This issue describes a feature request in Radius label May 20, 2024
@radius-triage-bot
Copy link

👋 @Reshrahim Thanks for filing this feature request.

A project maintainer will review this feature request and get back to you soon.

We also welcome community contributions! If you would like to pick this item up sooner and submit a pull request, please visit our contribution guidelines and assign this to yourself by commenting "/assign" on this issue.

For more information on our triage process please visit our triage overview

@willtsai willtsai added the triaged This issue has been reviewed and triaged label May 23, 2024
@radius-triage-bot
Copy link

👍 We've reviewed this issue and have agreed to add it to our backlog. Please subscribe to this issue for notifications, we'll provide updates when we pick it up.

We also welcome community contributions! If you would like to pick this item up sooner and submit a pull request, please visit our contribution guidelines and assign this to yourself by commenting "/assign" on this issue.

For more information on our triage process please visit our triage overview

This was referenced Jun 24, 2024
kachawla pushed a commit that referenced this issue Jul 3, 2024
# Description

Add model changes for supporting AWS IRSA credential

## Type of change

- This pull request adds or changes features of Radius and has an
approved issue (issue link required).

#7618

#

Partially Fixes: #7618

---------

Signed-off-by: nithyatsu <nithyasu@microsoft.com>
sk593 pushed a commit that referenced this issue Jul 10, 2024
# Description

Add model changes for supporting AWS IRSA credential

## Type of change

- This pull request adds or changes features of Radius and has an
approved issue (issue link required).

#7618

#

Partially Fixes: #7618

---------

Signed-off-by: nithyatsu <nithyasu@microsoft.com>
kachawla pushed a commit that referenced this issue Jul 16, 2024
# Description

Add convertor and controllers for the new IRSA credential type

## Type of change

- This pull request adds or changes features of Radius and has an
approved issue (issue link required).

Partially Fixes: #7618

---------

Signed-off-by: nithyatsu <nithyasu@microsoft.com>
Signed-off-by: Nithya Subramanian <98416062+nithyatsu@users.noreply.github.com>
sk593 pushed a commit that referenced this issue Jul 22, 2024
# Description

Add model changes for supporting AWS IRSA credential

## Type of change

- This pull request adds or changes features of Radius and has an
approved issue (issue link required).

#7618

#

Partially Fixes: #7618

---------

Signed-off-by: nithyatsu <nithyasu@microsoft.com>
sk593 pushed a commit that referenced this issue Jul 22, 2024
# Description

Add convertor and controllers for the new IRSA credential type

## Type of change

- This pull request adds or changes features of Radius and has an
approved issue (issue link required).

Partially Fixes: #7618

---------

Signed-off-by: nithyatsu <nithyasu@microsoft.com>
Signed-off-by: Nithya Subramanian <98416062+nithyatsu@users.noreply.github.com>
kachawla added a commit that referenced this issue Jul 29, 2024
# Description

Add server side support for AWS IRSA. 
UCP handles AWS resource deployment and needs irsa suuport.
Terraform provider communicates with AWS directly and needs IRSA support
too.

## Type of change
- This pull request adds or changes features of Radius and has an
approved issue (issue link required).

Partially Fixes: #7618

---------

Signed-off-by: nithyatsu <nithyasu@microsoft.com>
Signed-off-by: Nithya Subramanian <98416062+nithyatsu@users.noreply.github.com>
Co-authored-by: Karishma Chawla <kachawla@microsoft.com>
lakshmimsft pushed a commit that referenced this issue Jul 30, 2024
# Description

rad credential show should work with the new datamodel that supports 2
aws credential types - accesskey and irsa

## Type of change

- This pull request adds or changes features of Radius and has an
approved issue (issue link required).
Partially Fixes: #7618

---------

Signed-off-by: nithyatsu <nithyasu@microsoft.com>
Reshrahim pushed a commit to Reshrahim/radius that referenced this issue Aug 27, 2024
# Description

Add model changes for supporting AWS IRSA credential

## Type of change

- This pull request adds or changes features of Radius and has an
approved issue (issue link required).

radius-project#7618

#

Partially Fixes: radius-project#7618

---------

Signed-off-by: nithyatsu <nithyasu@microsoft.com>
Signed-off-by: Reshma Abdul Rahim <reshmarahim.abdul@microsoft.com>
Reshrahim pushed a commit to Reshrahim/radius that referenced this issue Aug 27, 2024
# Description

Add convertor and controllers for the new IRSA credential type

## Type of change

- This pull request adds or changes features of Radius and has an
approved issue (issue link required).

Partially Fixes: radius-project#7618

---------

Signed-off-by: nithyatsu <nithyasu@microsoft.com>
Signed-off-by: Nithya Subramanian <98416062+nithyatsu@users.noreply.github.com>
Signed-off-by: Reshma Abdul Rahim <reshmarahim.abdul@microsoft.com>
Reshrahim pushed a commit to Reshrahim/radius that referenced this issue Aug 27, 2024
# Description

Add server side support for AWS IRSA.
UCP handles AWS resource deployment and needs irsa suuport.
Terraform provider communicates with AWS directly and needs IRSA support
too.

## Type of change
- This pull request adds or changes features of Radius and has an
approved issue (issue link required).

Partially Fixes: radius-project#7618

---------

Signed-off-by: nithyatsu <nithyasu@microsoft.com>
Signed-off-by: Nithya Subramanian <98416062+nithyatsu@users.noreply.github.com>
Co-authored-by: Karishma Chawla <kachawla@microsoft.com>
Signed-off-by: Reshma Abdul Rahim <reshmarahim.abdul@microsoft.com>
Reshrahim pushed a commit to Reshrahim/radius that referenced this issue Aug 27, 2024
# Description

rad credential show should work with the new datamodel that supports 2
aws credential types - accesskey and irsa

## Type of change

- This pull request adds or changes features of Radius and has an
approved issue (issue link required).
Partially Fixes: radius-project#7618

---------

Signed-off-by: nithyatsu <nithyasu@microsoft.com>
Signed-off-by: Reshma Abdul Rahim <reshmarahim.abdul@microsoft.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature This issue describes a feature request in Radius triaged This issue has been reviewed and triaged
Projects
None yet
2 participants