Can we associate K8s serviceAccount with multiple aws IAM role

2.2k Views Asked by At

is it possible in eks to associate serviceAccount with multiple aws IAM roles? am I allowed to provide multiple arns in service account annotations? eg


apiVersion: v1
kind: ServiceAccount
metadata:
  name: Testxxx
  annotations:
    eks.amazonaws.com/role-arn: arn:aws:iam::123456789:role/A-role, arn:aws:iam::987654321:role/B-role

1

There are 1 best solutions below

0
Jeremy Cowan On

The short answer is no. You can, however, use the AWS SDKs to assume another role provided the role assigned to the service account includes AssumeRole. See Assume role with STS using an AWS SDK for additional information.