Skip to content

Commit b465681

Browse files
ThirdEyeSqueegeeeasymrgr
authored andcommitted
feat: add aws-secrets-store-csi-driver-provider documentation
cr: https://code.amazon.com/reviews/CR-232836543
1 parent a466986 commit b465681

File tree

1 file changed

+24
-0
lines changed

1 file changed

+24
-0
lines changed

latest/ug/workloads/workloads-add-ons-available-eks.adoc

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -98,6 +98,10 @@ You can use any of the following Amazon EKS add-ons.
9898
|<<add-ons-sriov-network-metrics-exporter>>
9999
|EC2
100100

101+
|Retrieve secrets from {aws} Secrets Manager and parameters from {aws} Systems Manager Parameter Store and mount them as files in Kubernetes pods.
102+
|<<add-ons-aws-secrets-store-csi-driver-provider>>
103+
|EC2, EKS Auto Mode, EKS Hybrid Nodes
104+
101105

102106
|===
103107

@@ -662,6 +666,26 @@ The SR-IOV Network Metrics Exporter Amazon EKS add-on collects and exposes metri
662666

663667
NOTE: This add-on requires nodes with SR-IOV-capable network interfaces.
664668

669+
[#add-ons-aws-secrets-store-csi-driver-provider]
670+
=== {aws} Secrets Store CSI Driver provider
671+
672+
The {aws} provider for the Secrets Store CSI Driver is an add-on that enables retrieving secrets from {aws} Secrets Manager and parameters from {aws} Systems Manager Parameter Store and mounting them as files in Kubernetes pods.
673+
674+
[#add-ons-ascp-iam-permissions]
675+
=== Required IAM permissions
676+
677+
The add-on does not require IAM permissions. However, application pods will require IAM permissions to fetch secrets from {aws} Secrets Manager and parameters from {aws} Systems Manager Parameter Store. After installing the add-on, access must be configured via IAM Roles for Service Accounts (IRSA) or EKS Pod Identity. To use IRSA, please refer to the Secrets Manager https://docs.aws.amazon.com/secretsmanager/latest/userguide/integrating_ascp_irsa.html[IRSA setup documentation]. To use EKS Pod Identity, please refer to the Secrets Manager https://docs.aws.amazon.com/secretsmanager/latest/userguide/ascp-pod-identity-integration.html[Pod Identity setup documentation].
678+
679+
{aws} suggests the `AWSSecretsManagerClientReadOnlyAccess` managed policy.
680+
681+
For more information about the required permissions, see `AWSSecretsManagerClientReadOnlyAccess` in the {aws} Managed Policy Reference.
682+
683+
=== Additional information
684+
685+
For more information, please see the secrets-store-csi-driver-provider-aws https://github.com/aws/secrets-store-csi-driver-provider-aws[GitHub repository].
686+
687+
To learn more about the add-on, please refer to the https://docs.aws.amazon.com/secretsmanager/latest/userguide/ascp-eks-installation.html[{aws} Secrets Manager documentation for the add-on].
688+
665689
[%header,cols="2"]
666690
|===
667691
|Property

0 commit comments

Comments
 (0)