You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: apis/elbv2/v1alpha1/targetgroupbinding_types.go
+7Lines changed: 7 additions & 0 deletions
Original file line number
Diff line number
Diff line change
@@ -136,6 +136,13 @@ type TargetGroupBindingSpec struct {
136
136
// IAM Role ARN to assume when calling AWS APIs. Needed to assume a role in another account and prevent the confused deputy problem. https://docs.aws.amazon.com/IAM/latest/UserGuide/confused-deputy.html
Copy file name to clipboardExpand all lines: apis/elbv2/v1beta1/targetgroupbinding_types.go
+7Lines changed: 7 additions & 0 deletions
Original file line number
Diff line number
Diff line change
@@ -171,6 +171,13 @@ type TargetGroupBindingSpec struct {
171
171
// IAM Role ARN to assume when calling AWS APIs. Needed to assume a role in another account and prevent the confused deputy problem. https://docs.aws.amazon.com/IAM/latest/UserGuide/confused-deputy.html
Copy file name to clipboardExpand all lines: docs/guide/targetgroupbinding/targetgroupbinding.md
+42Lines changed: 42 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -143,6 +143,7 @@ Use this feature when you need to manage TargetGroups in a different AWS account
143
143
**Spec fields:**
144
144
* `iamRoleArnToAssume`: The ARN of the role in the TGO account that the controller will assume
145
145
* `assumeRoleExternalId`: External ID for the assume role operation (optional but recommended to prevent the [confused deputy problem](https://docs.aws.amazon.com/IAM/latest/UserGuide/confused-deputy.html))
146
+
* `registerTargetsWithPodAvailabilityZone`: Register cross-account IP targets with the availability zone of the pod's node instead of `all`. See [Availability zones for cross-account targets](#availability-zones-for-cross-account-targets). Requires `iamRoleArnToAssume`.
146
147
147
148
148
149
### Sample YAML
@@ -244,6 +245,47 @@ Add the following permission to the AWS Load Balancer Controller's IAM role. Thi
244
245
}
245
246
```
246
247
248
+
### Availability zones for cross-account targets
249
+
250
+
By default, cross-account IP targets are registered with `AvailabilityZone: all`. Every zonal node of
251
+
the load balancer can then forward to every target, so turning off cross-zone load balancing has no
252
+
effect and inter-AZ data transfer charges are unavoidable.
253
+
254
+
Set `registerTargetsWithPodAvailabilityZone: true` to register each target with the availability zone
255
+
of the node its pod runs on. With cross-zone load balancing disabled, a zonal load balancer node then
256
+
only forwards to targets in its own zone.
257
+
258
+
Availability zone *names* are randomized per AWS account — `us-west-2a` in the CO account is usually a
259
+
different physical zone than `us-west-2a` in the TGO account. Availability zone *IDs* (for example
260
+
`usw2-az1`) are stable, so the controller resolves the pod's zone name to a zone ID in the CO account
261
+
and then back to the matching zone name in the TGO account. Both lookups use
262
+
`ec2:DescribeAvailabilityZones`, so the TGO role from Step 2 needs it:
263
+
264
+
```json
265
+
{
266
+
"Effect": "Allow",
267
+
"Action": [
268
+
"ec2:DescribeAvailabilityZones"
269
+
],
270
+
"Resource": "*"
271
+
}
272
+
```
273
+
274
+
!!!note ""
275
+
The zone must be one the load balancer has a subnet in. If a cluster runs nodes in a zone the load
276
+
balancer does not use, registration is rejected and the TargetGroupBinding reports an error.
277
+
278
+
!!!note ""
279
+
If the zone cannot be translated — for instance when the TGO role is missing
280
+
`ec2:DescribeAvailabilityZones`— the controller logs the failure and falls back to
281
+
`AvailabilityZone: all` rather than failing registration.
282
+
283
+
!!!note ""
284
+
The setting only affects targets registered after it is set. Targets that are already registered
285
+
keep their current availability zone (`all` or a zone name) until they are deregistered and
286
+
registered again, for example when the pod is replaced. This avoids disrupting live traffic when
287
+
the setting is toggled on an existing TargetGroupBinding.
288
+
247
289
248
290
## MultiCluster TargetGroup
249
291
TargetGroupBinding CR supports sharing the same TargetGroup ARN among multiple TargetGroupBindings. Setting this flag allows
0 commit comments