Skip to content

Commit c6468aa

Browse files
authored
docs: additional externalid entry for EKS Pod Identity role (#8737)
1 parent fd93867 commit c6468aa

File tree

1 file changed

+12
-0
lines changed

1 file changed

+12
-0
lines changed

_partials/eks-pod-identity/_eks-pod-identity-prerequisites.mdx

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -430,6 +430,18 @@ partial_name: eks-pod-identity-prerequisites
430430
}
431431
}
432432
},
433+
{
434+
"Effect": "Allow",
435+
"Principal": {
436+
"AWS": "arn:aws:iam::<aws-management-cluster-account-id>:role/<role-name-for-identity-service-iam-local-role>"
437+
},
438+
"Action": "sts:AssumeRole",
439+
"Condition": {
440+
"StringLike": {
441+
"sts:ExternalId": "<aws-management-cluster-region>/<aws-management-cluster-account-id>/<management-cluster-name>/*/palette-manager"
442+
}
443+
}
444+
},
433445
{
434446
"Effect": "Allow",
435447
"Principal": {

0 commit comments

Comments
 (0)