Panel | ||||||
---|---|---|---|---|---|---|
| ||||||
Note |
Permission required by Kyvos Managed Identity
Panel | ||||||
---|---|---|---|---|---|---|
| ||||||
Important These are only required when the AKS cluster is created externally, and you want to configure it post-deployment/post upgrade) from Kyvos Manager. |
Case 1: Dedicated Azure Kubernetes Service (AKS) Cluster
...
Built-in Azure Kubernetes Service Cluster User Role on the AKS cluster
Built-in Reader on the AKS cluster
Built-in Virtual Machine Contributor on VMSS of Node pool
Microsoft.ContainerService/managedClusters/agentPools/write" on the AKS cluster
Microsoft.ContainerService/managedClusters/agentPools/read" on the AKS cluster
Microsoft.ContainerService/managedClusters/agentPools/delete" on the AKS cluster
Case 4: Shared Node pool
Built-in Azure Kubernetes Service Cluster User Role on the AKS cluster
Built-in Reader on the AKS cluster
Permission required by Kubernetes Managed Identity
Built-in Managed Identity Operator on this Managed Identity itself
...
panelIconId | atlassian-note |
---|---|
panelIcon | :note: |
bgColor | #DEEBFF |
...
Built-in Storage Blob Data Contributor on the Kyvos storage account
Built-in Reader on the AKS cluster
Create Access policy to get secret on the Kyvos key Vault
Enhanced Security
AKS Subnet must be allowed in networking rules of Kyvos storage account.
AKS Subnet must be allowed in networking rules of Kyvos key Vault.
...