Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RRSA (RamRoleforServiceAccount) support for Alibaba Cloud #5019

Open
NIZ-elsevier opened this issue Jan 20, 2025 · 4 comments
Open

RRSA (RamRoleforServiceAccount) support for Alibaba Cloud #5019

NIZ-elsevier opened this issue Jan 20, 2025 · 4 comments
Labels
help wanted Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines. kind/feature Categorizes issue or PR as related to a new feature.

Comments

@NIZ-elsevier
Copy link

NIZ-elsevier commented Jan 20, 2025

What would you like to be added: RRSA (RamRoleforServiceAccount) authentication support for Alibaba Cloud

Why is this needed:

Similar to IRSA in AWS, applications in a Pod’s containers can make requests to Alicloud APIs with dedicated roles to the service account. This will allow the external dns pod to use the service account to get the credentials from the RAM role, not using the worker node instance role anymore, which is a much more secured approach.

As now Alicloud has provided wider support of RRSA, I would like to request the same feature for external-dns, following other components such as ack-secret-manager.

The similar issue was raised here. The vendor is instructing me to raise it again.

@NIZ-elsevier NIZ-elsevier added the kind/feature Categorizes issue or PR as related to a new feature. label Jan 20, 2025
@ivankatliarchuk
Copy link
Contributor

Hi Niz, this project is primarily community-maintained. Implementing this feature might require in-depth knowledge of Alibaba Cloud, which could be challenging for us. Would you be willing to submit a pull request?

@NIZ-elsevier
Copy link
Author

Hi @ivankatliarchuk, thank you for your quick reply. I am contacting with the vendor Alibaba Cloud about this, see if they can help us to provide the feature, as they know the best of RRSA.

We are the end user of the product. If we have the capacity, we will definitely consider contributing to the project ourselves.

@ivankatliarchuk
Copy link
Contributor

/help

@k8s-ci-robot
Copy link
Contributor

@ivankatliarchuk:
This request has been marked as needing help from a contributor.

Guidelines

Please ensure that the issue body includes answers to the following questions:

  • Why are we solving this issue?
  • To address this issue, are there any code changes? If there are code changes, what needs to be done in the code and what places can the assignee treat as reference points?
  • Does this issue have zero to low barrier of entry?
  • How can the assignee reach out to you for help?

For more details on the requirements of such an issue, please see here and ensure that they are met.

If this request no longer meets these requirements, the label can be removed
by commenting with the /remove-help command.

In response to this:

/help

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@k8s-ci-robot k8s-ci-robot added the help wanted Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines. label Jan 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
help wanted Denotes an issue that needs help from a contributor. Must meet "help wanted" guidelines. kind/feature Categorizes issue or PR as related to a new feature.
Projects
None yet
Development

No branches or pull requests

3 participants