Does Thanos Store support Amazon EKS Pod Identity Agent for service accounts? #7156
Unanswered
jonsbun
asked this question in
Questions & Answers
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I am trying to switch Thanos Store AWS S3 object storage authentication from the old fashion "IAM roles for service accounts (IRSA)", to the new approach via "EKS Pod Identities".
However, I always getting bucket store initial sync: sync block: BaseFetcher: iter bucket: Access Denied:
Object storage config:
My main question is does Thanos Store support authentication via EKS Pod Identity or only old way via Web Identity works? I can access S3 Thanos storage bucket via Web Identity and IAM role without problems.
However, no luck via EKS Pod Identity. I am sure that EKS Pod Identity solution is working because I can access S3 bucket using Thanos store Statefulset initContainer and
amazon/aws-cli
image and the same service accountthanos-storegateway
.Any ideas?
Beta Was this translation helpful? Give feedback.
All reactions