Loading...
Loading...
Follow this guide to provide appropriate Veeam Kasten for Kubernetes role-based access using AWS IAM users or roles.
Description Veeam Kasten for Kubernetes integrates with whatever authentication mechanism customers use to access their Kubernetes clusters. Since EKS natively supports AWS IAM authentication, AWS IAM users/roles can be used to delegate access. See (Managing Users or IAM Roles for your Cluster) for general instructions on providing appropriate access. For Veeam Kasten for Kubernetes specifically, this involves updating the aws-auth ConfigMap in the kube-system namespace and mapping the specific IAM user or role to a Kubernetes user or group (e.g., k10-admins). That Kubernetes user or group can then be bound to one of the Kubernetes roles created by Veeam Kasten for Kubernetes using a ClusterRoleBinding or RoleBinding. How it works kubectl When the user invokes kubectl to access the cluster, kubectl contacts the local aws-iam-authenticator tool to get a Kubernetes bearer token and uses that for authentication. The server-side aws-iam-authenticator handles validation and maps the user to the group specified above in aws-creds. Dashboard access To access a dashboard for a cluster setup in EKS with token authentication, the user must obtain a token from the command line. This can be done via the aws-iam-authenticator tool by running the command:
Click on a version to see all relevant bugs
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.