Skip to main content

okustera_iam_role (Resource)

Declares and manages an in-cluster IAM role defining fine-grained API route authorizations, scoped OpenStack Keystone permissions, and Ceph S3 access policies.

Example Usage​

Fine-Grained Workload IAM Role​

resource "okustera_iam_role" "data_processor" {
name = "data-processor-role"
namespace = "production"
description = "Allows data processor pods to access S3 storage and compute APIs"

endpoint_policies = [
{
effect = "Allow"
paths = ["/api/v1/storage/buckets/*"]
methods = ["GET", "POST", "PUT"]
},
{
effect = "Deny"
paths = ["/api/v1/billing/*"]
methods = ["*"]
}
]

openstack_policy = {
enabled = true
project_scope = "production-tenant"
roles = ["reader"]
services = ["compute", "network"]
}

s3_policy = {
enabled = true
buckets = ["data-lake-raw", "data-lake-processed"]
actions = ["s3:GetObject", "s3:PutObject"]
}
}

Schema​

Required​

  • name (String, Forces new resource) Unique name of the IAM role.

Optional​

  • description (String) Human-readable description of the role's purpose.
  • endpoint_policies (Attributes List) List of fine-grained REST endpoint authorization rules. (see below for nested schema)
  • namespace (String, Forces new resource) Kubernetes namespace scoping the role. Defaults to default.
  • openstack_policy (Attributes) Scoped OpenStack Keystone role and service delegation policy. (see below for nested schema)
  • s3_policy (Attributes) Scoped Ceph Object Gateway (S3/RGW) bucket and action permissions. (see below for nested schema)
  • tenant_id (String) Okustera project/tenant UUID owning this role.

Read-Only​

  • binding_count (Number) Number of active Pod identity bindings referencing this role.
  • created_at (String) Timestamp when IAM role was created.
  • id (String) Combined role identifier (<namespace>/<name>).

Nested Schema for endpoint_policies​

Required:

  • effect (String) Authorization effect: Allow or Deny.
  • methods (List of String) Allowed HTTP methods (e.g. GET, POST, *).
  • paths (List of String) API URL path patterns (e.g. /api/v1/storage/*).

Nested Schema for openstack_policy​

Required:

  • enabled (Boolean) Enable OpenStack scoped token minting.

Optional:

  • project_scope (String) Scoped Keystone project ID or name.
  • roles (List of String) Keystone roles granted (e.g. member, reader).
  • services (List of String) OpenStack services permitted (e.g. compute, network, volumev3).

Nested Schema for s3_policy​

Required:

  • enabled (Boolean) Enable S3 STS credential minting.

Optional:

  • actions (List of String) Allowed S3 actions (e.g. s3:GetObject, s3:PutObject).
  • buckets (List of String) Allowed S3 bucket names (or * for all tenant buckets).

Import​

IAM roles can be imported using <namespace>/<name> or <name>:

terraform import okustera_iam_role.example "production/data-processor-role"