Comments (1)
My colleague at work has provided me with guidance on the solution to this problem. This solution is specific to GitLab Runner in Kubernetes. Hopefully it will help someone who is also stuck in the same situation.
Solution
When deploying the runner using helm, you need to add a podAnnotations
property iam.amazonaws.com/role
as the sub-property under runners
in the values.yml file.
It should look something like this:
runners:
podAnnotations:
iam.amazonaws.com/role: my-iam-role
Setting iam.amazonaws.com/role
directly under the podAnnotations
provided in values.yml is incorrect because GitLab runner pod is used to checkin with the GitLab server for new jobs to execute and not the actual Pod that will be executing the CICD pipeline. This is done by the executor. By adding podAnnotations
the way specified above, the executor will contain the annotation to obtain the required IAM role.
The steps will be as follows
- Edit values.yml file to fit your requirements and add
podAnnotations
section as specified above. helm repo add gitlab https://charts.gitlab.io
helm install --namespace <NAMESPACE> gitlab-runner -f <CONFIG_VALUES_FILE> gitlab/gitlab-runner
If you are updating an existing installation:
- Edit values.yml file to fit your requirements and add
podAnnotations
section as specified above. helm repo update
helm upgrade --namespace <NAMESPACE> -f <CONFIG_VALUES_FILE> <RELEASE-NAME> gitlab/gitlab-runner
from kube2iam.
Related Issues (20)
- any catastrophic reaction if we enable liveness probe?
- The assume role policy documentation on the README is confusing
- multi arch docker image for 0.11.0 HOT 7
- eks 1.22 HOT 4
- [Namespace restriction] Regex cannot be as strict as expected
- Update release version in hub.docker.com HOT 1
- Dependency requires Go 1.17, which kube2iam fails to build with
- Ec2 Metadata updgrade from imdSV1 to imdSV2 causes 403 and 401 error- kube2iam HOT 1
- The security token included in the request is expired - JAVA SDK HOT 6
- At times few Kube2iam pods ending up in pending state
- AWS Trust Policy Behavior Change
- imdsv2 failing for kube2iam deployed on azure aks to assume aws iam role.
- Release Charts action is failing HOT 2
- Add helm chart with ARM support HOT 1
- Can you use kube2iam with a local kubernetes cluster?
- Kube2iam helm support for custom securityContext
- The `/github subscribe [repository name]` Command Fails To Subscribe
- How to use kube2iam on self hosted cluster
- Request failing with error "pod with specificed IP not found"
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from kube2iam.