Cross Account IRSA for multi-account cluster #6834
Unanswered
prasoon-pxc
asked this question in
Community support Q&A
Replies: 1 comment 3 replies
-
I have not tried this out myself but this might be possible by configuring the dev EKS cluster to use the OIDC provider used for the staging clusters. Assuming that the S3 bucket is in the same AWS account as the staging clusters, you can create a role that gives federated users access to the bucket and then update the annotation in the Velero service account in the dev cluster. The procedure should be similar to the one described in this blog post: Thanks, Md (CloudCasa). |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I have three EKS clusters which is running on three different AWS account , for now I have installed velero on every clusters separately and it is working fine and I am using IRSA based access for S3-bucket and volume-snapshot.
Now, I have requirement that I want to take backup from my dev clusters(test-ns1) and store it in a staging clusters(test-ns-1), i know that I have to use same S3-bucket for both accounts for it to work, but how can I pass credentials for dev-bucket to staging bucket using IRSA based access
Beta Was this translation helpful? Give feedback.
All reactions