sts:AssumeRoleWithWebIdentity
Jump to navigation
Jump to search
sts:AssumeRoleWithWebIdentity
Official example[edit]
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Federated": "arn:aws:iam::111122223333:oidc-provider/oidc.eks.region-code.amazonaws.com/id/EXAMPLED539D4633E53DE1B71EXAMPLE"
},
"Action": "sts:AssumeRoleWithWebIdentity",
"Condition": {
"StringEquals": {
"oidc.eks.region-code.amazonaws.com/id/EXAMPLED539D4633E53DE1B71EXAMPLE:aud": "sts.amazonaws.com",
"oidc.eks.region-code.amazonaws.com/id/EXAMPLED539D4633E53DE1B71EXAMPLE:sub": "system:serviceaccount:kube-system:ebs-csi-controller-sa"
}
}
}
]
}
ref: Managing the Amazon EBS CSI driver as an Amazon EKS add-on
(combined from similar events): failed to provision volume with StorageClass "gp2": rpc error: code = Internal desc = Could not create volume "pvc-641db932-4715-4f5a-b2d2-9c0c4117dd27": could not create volume in EC2: WebIdentityErr: failed to retrieve credentials caused by: AccessDenied: Not authorized to perform sts:AssumeRoleWithWebIdentity status code: 403, request id: 6bc69eb4-96a6-4167-b5e3-1234567890
Activities[edit]
- Managing the Amazon EBS CSI driver as an Amazon EKS add-on
- Configuring a Kubernetes service account to assume an IAM role
Related[edit]
- Could not create volume in EC2
- Terraform Dynamic Credentials Setup Examples
aws-node: system:serviceaccount:kubesystem:aws-nodeaws_iam_role- data.aws_iam_policy_document
See also[edit]
ebs-csi: ebs.csi.aws.com, aws-ebs-csi-driver: Installation, ProvisioningFailed, sts:AssumeRoleWithWebIdentity, Volume Modification- sts:AssumeRole
sts:, sts:TagSession, sts:AssumeRole, sts:AssumeRoleWithWebIdentity, sts:AssumeRoleWithSAML- Kubernetes Persistent Volume Claim (PVC) (
kind: PersistentVolumeClaim), Kubernetes Persistent volumes (PV)(kind: PersistentVolume),kubectl describe pvc, kubectl get pvc, ClaimLost, ProvisioningSucceeded, PV access control, PersistentVolumeClaimRetentionPolicy
Advertising: