<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Iam on DevOps &amp; Rock&#39;N&#39;Roll</title>
    <link>https://artazar.pages.dev/tags/iam/</link>
    <description>Recent content in Iam on DevOps &amp; Rock&#39;N&#39;Roll</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Wed, 19 Aug 2026 15:55:02 +0700</lastBuildDate>
    <atom:link href="https://artazar.pages.dev/tags/iam/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>IRSA to Pod Identity: notes from the migration</title>
      <link>https://artazar.pages.dev/blog/10-irsa-to-pod-identity/</link>
      <pubDate>Tue, 02 Jun 2026 00:08:30 +0000</pubDate>
      <guid>https://artazar.pages.dev/blog/10-irsa-to-pod-identity/</guid>
      <description>&lt;p&gt;IRSA has been the way to give a Kubernetes pod an AWS identity since 2019, and it works. It also requires an OIDC provider per cluster, a trust policy per role that names a specific cluster&amp;rsquo;s OIDC issuer, and a mental model involving projected service account tokens that you re-derive from scratch every time something breaks.&lt;/p&gt;&#xA;&lt;p&gt;EKS Pod Identity does the same job with less machinery. I&amp;rsquo;ve now moved a few clusters over and it&amp;rsquo;s mostly good news, with a couple of edges worth knowing before you start.&lt;/p&gt;</description>
    </item>
    <item>
      <title>EKS Access Entries: one ARN, one cluster, no sharing</title>
      <link>https://artazar.pages.dev/blog/07-eks-access-entries/</link>
      <pubDate>Tue, 21 Apr 2026 00:08:30 +0000</pubDate>
      <guid>https://artazar.pages.dev/blog/07-eks-access-entries/</guid>
      <description>&lt;p&gt;EKS Access Entries replaced the &lt;code&gt;aws-auth&lt;/code&gt; ConfigMap and made cluster authorization a proper AWS API object instead of a YAML blob that you edited with trembling hands, hoping you wouldn&amp;rsquo;t lock yourself out. It&amp;rsquo;s a genuine improvement. But moving auth into the API surface also moves it into Terraform state, and that&amp;rsquo;s where it gets interesting.&lt;/p&gt;&#xA;&lt;p&gt;The error that sent me down this road:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Error: creating EKS Access Entry (test-spain-001:arn:aws:iam::123456789012:role/PlatformAdmin):&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;ResourceInUseException: The specified access entry resource is already in use&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;on this cluster.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;My first reaction was the wrong one: &lt;em&gt;are access entries global? Did creating one for cluster A break cluster B?&lt;/em&gt;&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
