Lambda connecting to EKS failed even after setting up RBAC authorization

Viewed 142

I have setup a lamdba function that needs to call connect to EKS and call the API server to get the list of nodes. I have setup the authorization correctly however I still see that the API server is recognizing the lambda as anonymous Below is the error I get

HTTP response body: 
{
    "kind": "Status",
    "apiVersion": "v1",
    "metadata": {},
    "status": "Failure",
    "message": "nodes is forbidden: User \"system:anonymous\" cannot list resource \"nodes\" in API group \"\" at the cluster scope",
    "reason": "Forbidden",
    "details": {
        "kind": "nodes"
    },
    "code": 403
}

I have the added the lambda role arn in my aws-auth configmap.

    - groups:
      - system:masters
      rolearn: arn:aws:iam::{account_id}:role/{lambda_name}

Also the lambda has permissions to perform all actions on all the resources in the eks in its policy.

Any idea what I may be missing here?

1 Answers

Seeing system:anonymous in the response makes me think the request isn't being authenticated correctly.

EKS expects a bearer token built from a presigned STS get-caller-identity URL. The code for this is here: https://github.com/kubernetes-sigs/aws-iam-authenticator#api-authorization-from-outside-a-cluster

You can configure the client from a dictionary very similar to the kubeconfig file. You'll need the cluster_ca and cluster_endpoint which you can get from the describe_cluster API.

kubeconfig = {
    'apiVersion': 'v1',
    'clusters': [{
        'name': 'cluster1',
        'cluster': {
        'certificate-authority-data': cluster_ca,
        'server': cluster_endpoint}
    }],
    'contexts': [{'name': 'context1', 'context': {'cluster': 'cluster1', "user": "user1"}}],
    'current-context': 'context1',
    'kind': 'Config',
    'preferences': {},
    'users': [{'name': 'user1', "user" : {'token': get_bearer_token()}}]
}

config.load_kube_config_from_dict(config_dict=kubeconfig)
v1_api = client.CoreV1Api()

If you are still getting an error enable control plane authenticator logging. You'll see 'access denied' messages in there that include the identity ARN.

Related