AmazonEBSCSIDriverEKSClusterScopedPolicy

AWS IAM · Containers · Specialized

AmazonEBSCSIDriverEKSClusterScopedPolicy

SpecializedIAM ScopeContainers

Dado verificado em · Fonte

Tipo

AWS Managed

Escopo

account

Amazon Resource Name (ARN)

arn:aws:iam::aws:policy/AmazonEBSCSIDriverEKSClusterScopedPolicy

Descrição

IAM Policy that allows the CSI driver service account to make calls to related services such as EC2 on your behalf. This policy restricts the Amazon EBS CSI driver to only managing EBS volumes and snapshots that belong to a specific EKS cluster. It requires the resource tag ebs.csi.aws.com/cluster-name to match the eks-cluster-name tag on the IAM principal, preventing cross-cluster access when multiple clusters share the same AWS account. Attach and detach operations on instances are restricted to instances tagged with either the eks:cluster-name tag (set automatically by EKS on managed node groups) or the ebs.csi.aws.com/cluster-name tag (for manually tagged instances).

Specialized

Narrow-purpose policies for specific use cases or service integrations

Detalhes da policy — dados da AWS

Tipo
AWS managed policy
Criada em
April 16, 2026, 17:27 UTC
Última edição
May 28, 2026, 17:27 UTC
Versão
v2 (default)

IAM Actions (19)

Carregando actions…

IAM ActionServiçoOperaçãoEscopo
Nenhum resultado para “”.
Por página
Nenhum resultado

Carregando documento JSON…