okustera_iam_role (Resource)
Declares and manages an in-cluster IAM role defining fine-grained API route authorizations, scoped OpenStack Keystone permissions, and Ceph S3 access policies.
Example Usage
Fine-Grained Workload IAM Role
resource "okustera_iam_role" "data_processor" {
name = "data-processor-role"
namespace = "production"
description = "Allows data processor pods to access S3 storage and compute APIs"
endpoint_policies = [
{
effect = "Allow"
paths = ["/api/v1/storage/buckets/*"]
methods = ["GET", "POST", "PUT"]
},
{
effect = "Deny"
paths = ["/api/v1/billing/*"]
methods = ["*"]
}
]
openstack_policy = {
enabled = true
project_scope = "production-tenant"
roles = ["reader"]
services = ["compute", "network"]
}
s3_policy = {
enabled = true
buckets = ["data-lake-raw", "data-lake-processed"]
actions = ["s3:GetObject", "s3:PutObject"]
}
}
Schema
Required
name(String, Forces new resource) Unique name of the IAM role.
Optional
description(String) Human-readable description of the role's purpose.endpoint_policies(Attributes List) List of fine-grained REST endpoint authorization rules. (see below for nested schema)namespace(String, Forces new resource) Kubernetes namespace scoping the role. Defaults todefault.openstack_policy(Attributes) Scoped OpenStack Keystone role and service delegation policy. (see below for nested schema)s3_policy(Attributes) Scoped Ceph Object Gateway (S3/RGW) bucket and action permissions. (see below for nested schema)tenant_id(String) Okustera project/tenant UUID owning this role.
Read-Only
binding_count(Number) Number of active Pod identity bindings referencing this role.created_at(String) Timestamp when IAM role was created.id(String) Combined role identifier (<namespace>/<name>).
Nested Schema for endpoint_policies
Required:
effect(String) Authorization effect:AlloworDeny.methods(List of String) Allowed HTTP methods (e.g.GET,POST,*).paths(List of String) API URL path patterns (e.g./api/v1/storage/*).
Nested Schema for openstack_policy
Required:
enabled(Boolean) Enable OpenStack scoped token minting.
Optional:
project_scope(String) Scoped Keystone project ID or name.roles(List of String) Keystone roles granted (e.g.member,reader).services(List of String) OpenStack services permitted (e.g.compute,network,volumev3).
Nested Schema for s3_policy
Required:
enabled(Boolean) Enable S3 STS credential minting.
Optional:
actions(List of String) Allowed S3 actions (e.g.s3:GetObject,s3:PutObject).buckets(List of String) Allowed S3 bucket names (or*for all tenant buckets).
Import
IAM roles can be imported using <namespace>/<name> or <name>:
terraform import okustera_iam_role.example "production/data-processor-role"