ServiceAccount
- class aws_cdk.aws_eks.ServiceAccount(scope, id, *, cluster, annotations=None, identity_type=None, labels=None, name=None, namespace=None, overwrite_service_account=None)
Bases:
ConstructService Account.
- ExampleMetadata:
infused
Example:
# cluster: eks.Cluster eks.ServiceAccount(self, "ServiceAccount", cluster=cluster, name="test-sa", namespace="default", identity_type=eks.IdentityType.POD_IDENTITY )
- Parameters:
scope (
Construct)id (
str)cluster (
ICluster) – The cluster to apply the patch to.annotations (
Optional[Mapping[str,str]]) – Additional annotations of the service account. Default: - no additional annotationsidentity_type (
Optional[IdentityType]) – The identity type to use for the service account. Default: IdentityType.IRSAlabels (
Optional[Mapping[str,str]]) – Additional labels of the service account. Default: - no additional labelsname (
Optional[str]) – The name of the service account. The name of a ServiceAccount object must be a valid DNS subdomain name. https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/ Default: - If no name is given, it will use the id of the resource.namespace (
Optional[str]) – The namespace of the service account. All namespace names must be valid RFC 1123 DNS labels. https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/#namespaces-and-dns Default: “default”overwrite_service_account (
Optional[bool]) – Overwrite existing service account. If this is set, we will usekubectl applyinstead ofkubectl createwhen the service account is created. Otherwise, if there is already a service account in the cluster with the same name, the operation will fail. Default: false
Methods
- add_to_principal_policy(statement)
Add to the policy of this principal.
- Parameters:
statement (
PolicyStatement)- Return type:
- to_string()
Returns a string representation of this construct.
- Return type:
str
Attributes
- assume_role_action
When this Principal is used in an AssumeRole policy, the action to use.
- grant_principal
The principal to grant permissions to.
- node
The tree node.
- policy_fragment
Return the policy fragment that identifies this principal in a Policy.
- role
The role which is linked to the service account.
- service_account_name
The name of the service account.
- service_account_namespace
The namespace where the service account is located in.
Static Methods
- classmethod is_construct(x)
Checks if
xis a construct.Use this method instead of
instanceofto properly detectConstructinstances, even when the construct library is symlinked.Explanation: in JavaScript, multiple copies of the
constructslibrary on disk are seen as independent, completely different libraries. As a consequence, the classConstructin each copy of theconstructslibrary is seen as a different class, and an instance of one class will not test asinstanceofthe other class.npm installwill not create installations like this, but users may manually symlink construct libraries together or use a monorepo tool: in those cases, multiple copies of theconstructslibrary can be accidentally installed, andinstanceofwill behave unpredictably. It is safest to avoid usinginstanceof, and using this type-testing method instead.- Parameters:
x (
Any) – Any object.- Return type:
bool- Returns:
true if
xis an object created from a class which extendsConstruct.