Crossplane with podIdentity
In this example, I will be using podIdentity for crossplane as well as resources created by it. Instructions covers
- Installation of Crossplane with podIdentity
- Configure Corssplane to use PodIdentity for IAM roles
- Create IAM roles and S3 buckets using crossplane provider aws
Step 1. IAM role for Crossplane
Create IAM role with PodIdentity assume role and create podIdentity association for the role. Attach necessary permisions to the role.
Step 2. Install Crossplane
helm repo add crossplane-stable https://charts.crossplane.io/stable
helm repo update
helm install crossplane \
--namespace crossplane-system \
--create-namespace \
crossplane-stable/crossplane
# Specify SA name if different than `crossplane`
Step 3. Create deployment runtime configs for providers
Create deployment runtime config per provider so that you can set resources for each of the providers. In package runtime, add arguments to reduce unnecesary memory usage