Adding or updating AWS tags for a hosted cluster
As a cluster instance administrator, you can add or update Amazon Web Services (AWS) tags without needing to re-create your hosted cluster. Tags are key-value pairs that are attached to AWS resources for management and automation.
You might want to use tags for the following purposes:
-
Managing access controls.
-
Tracking chargeback or showback.
-
Managing cloud Identity and Access Management (IAM) conditional permissions.
-
Aggregating resources based on tags. For example, you can query tags to calculate resource usage and billing costs.
You can add or update tags for several different types of resources, including Amazon Elastic File System (EFS) access points, load balancer resources, Amazon Elastic Block Storage (EBS) volumes, IAM users, and AWS S3.
|
|
On network load balancers, tags cannot be added or updated. The AWS load balancer reconciles whatever tags are in the In addition, tags cannot be updated on the default security group resource that is created directly by hosted control planes. |
-
You must have cluster administrator permissions for your hosted cluster on AWS.
-
If you want to add or update tags for EFS access points, complete steps 1 and 2. If you are adding or updating tags for other types of resources, complete only step 2.
-
In the
aws-efs-csi-driver-operatorservice account, add two annotations, as shown in the following example. These annotations are required so that the Amazon Elastic Kubernetes Service (EKS) pod identity webhook that runs on the cluster can correctly assign AWS roles to the pods that the EFS Operator uses.apiVersion: v1 kind: ServiceAccount metadata: name: <service_account_name> namespace: <project_name> annotations: eks.amazonaws.com/role-arn:<role_arn> eks.amazonaws.com/audience:sts.amazonaws.com -
Delete the Operator pod or roll out a restart of the
aws-efs-csi-driver-operatordeployment.
-
-
In the
HostedClusterresource, enter information in theresourceTagsfields, as shown in the following example:ExampleHostedClusterresourceapiVersion: hypershift.openshift.io/v1beta1 kind: HostedCluster metadata: #... spec: autoscaling: {} clusterID: <cluster_id> configuration: {} controllerAvailabilityPolicy: SingleReplica dns: #... etcd: #... fips: false infraID: <infra_id> infrastructureAvailabilityPolicy: SingleReplica issuerURL: https://<issuer_url>.s3.<region>.amazonaws.com networking: #... olmCatalogPlacement: management platform: aws: #... resourceTags: - key: kubernetes.io/cluster/<tag> value: owned rolesRef: #... type: AWSReplace
<tag>with the tag that you want to add to your resource.