Does Thanos Store support Amazon EKS Pod Identity Agent for service accounts? #7156
Unanswered
jonsbun
asked this question in
Questions & Answers
Replies: 2 comments 1 reply
-
bumping this issue as i was hoping this would work as well but it doesn't seem to be for me. |
Beta Was this translation helpful? Give feedback.
0 replies
-
Thanos supports EKS Pod Identity in main #7335. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I am trying to switch Thanos Store AWS S3 object storage authentication from the old fashion "IAM roles for service accounts (IRSA)", to the new approach via "EKS Pod Identities".
However, I always getting bucket store initial sync: sync block: BaseFetcher: iter bucket: Access Denied:
Object storage config:
My main question is does Thanos Store support authentication via EKS Pod Identity or only old way via Web Identity works? I can access S3 Thanos storage bucket via Web Identity and IAM role without problems.
However, no luck via EKS Pod Identity. I am sure that EKS Pod Identity solution is working because I can access S3 bucket using Thanos store Statefulset initContainer and
amazon/aws-cli
image and the same service accountthanos-storegateway
.Any ideas?
Beta Was this translation helpful? Give feedback.
All reactions