IRSA for non EKS Clusters | PlatformCon 2023

  Рет қаралды 862

Platform Engineering

Platform Engineering

Жыл бұрын

This talk discusses using IAM Roles for Service Accounts (IRSA) to provide secure access to AWS resources from within pods in EC2-based Kubernetes clusters. IRSA is a robust and fine-grained solution that is easy to set up and less prone to incidents than other solutions. It is backed by the OpenSource project Pod Identity Webhook and can be used on non-EKS clusters.
To provide secure access to AWS resources, we have been using Kiam & Kube2iam project on our EC2-based clusters. Many of the AWS Customers moved to Amazon EKS and then adopted IAM Roles for Service Accounts (IRSA). IRSA is a feature that enables secure access to AWS resources from within pods while also providing robust identity and access management capabilities.
IRSA is much more robust, more fine-grained and easy to set up and less prone to incidents compared to other solutions.
Speaker: Suraj Narwade
Sr. Platform Engineer, RVU
_____________
- Check all the PlatformCon talks: platformcon.com/talks
- Check all the PlatformCon tracks: platformcon.com/#conference-t...
- Join Platform Engineering Slack: platformengineering.org/slack-rd
#PlatformCon2023 #PlatformEngineering

Пікірлер: 2
@scatat
@scatat 8 ай бұрын
Wow - I'm surprised no-one has commented on this post! I have been tearing my hair out trying to figure out a way of setting up a single node K8 in AWS on EC2 without using EKS and this is the key to doing it! The repo is already there to find but you've shown up on a Google search and the way it's explained by you is clear and consise - wonderful. Thank you so much for this - it's saved me a huge amount of pain and hassle. Fantastic video.
@user-bl1ub2gu2q
@user-bl1ub2gu2q 7 ай бұрын
hi awesome video for a kickstart. would request to make detailed video step by step on kops irsa and how to use efs csi pv,pvc with kops!!
A little girl was shy at her first ballet lesson #shorts
00:35
Fabiosa Animated
Рет қаралды 14 МЛН
WHAT’S THAT?
00:27
Natan por Aí
Рет қаралды 14 МЛН
AWS re:Invent 2023 - The future of Amazon EKS (CON203)
56:03
AWS Events
Рет қаралды 8 М.
RBAC in Kubernetes
20:27
Pavan Elthepu
Рет қаралды 31 М.
Manage Pod Identity Associations in EKS Clusters using Rafay
3:57
OIDC and Workload Identity in Kubernetes - Ashutosh Kumar, Elastic & Anish Ramasekar, Microsoft
35:25
CNCF [Cloud Native Computing Foundation]
Рет қаралды 1,8 М.
Backstage is not your platform
1:00:31
Platform Engineering
Рет қаралды 1,3 М.
How do I troubleshoot an OIDC provider and IRSA in Amazon EKS?
7:12
Amazon Web Services
Рет қаралды 2 М.
What is EKS POD Identity?
15:24
Fast Track TechEd
Рет қаралды 1,5 М.
Kubernetes IAM Role For Service Accounts | Demo | Simply Explained
13:35
Execute on Command
Рет қаралды 3,8 М.
ToRung short film: i sell watermelon🍉
0:38
ToRung
Рет қаралды 20 МЛН
小路飞跟姐姐去哪里了#海贼王#路飞
0:45
路飞与唐舞桐
Рет қаралды 37 МЛН
Мыла наелся
0:21
Pavlov_family_
Рет қаралды 3,6 МЛН
Бабайка #юмор #рекомендации #прикол
0:32
МэдПринц 👑
Рет қаралды 1,9 МЛН
Stay on your way 🛤️✨
0:34
A4
Рет қаралды 21 МЛН