Skip to main content

okustera_pod_identity_binding (Resource)

Binds a Kubernetes ServiceAccount to an Okustera IAM role (okustera_iam_role), enabling Zero-Trust Pod Workload Identity where pods exchange projected OIDC tokens for temporary API Gateway STS session tokens without static secrets.

Example Usage​

Bind Spark Worker Pods to IAM Role​

resource "okustera_iam_role" "worker_role" {
name = "spark-worker-role"
namespace = "production"
s3_policy = {
enabled = true
buckets = ["spark-checkpoints"]
actions = ["*"]
}
}

resource "okustera_pod_identity_binding" "spark_binding" {
name = "spark-worker-binding"
namespace = "production"
service_account_name = "spark-worker-sa"
role_name = okustera_iam_role.worker_role.name
}

Schema​

Required​

  • name (String, Forces new resource) Unique name of the Pod identity binding.
  • role_name (String) Name of the okustera_iam_role to bind to.
  • service_account_name (String) Name of the target Kubernetes ServiceAccount.

Optional​

  • namespace (String, Forces new resource) Kubernetes namespace containing the ServiceAccount. Defaults to default.
  • role_namespace (String) Namespace of the okustera_iam_role (defaults to the binding namespace).

Read-Only​

  • bound_at (String) Timestamp when identity binding was established.
  • id (String) Combined binding identifier (<namespace>/<name>).

Import​

Pod identity bindings can be imported using <namespace>/<name> or <name>:

terraform import okustera_pod_identity_binding.example "production/spark-worker-binding"