okustera_pod_identity_binding (Resource)
Binds a Kubernetes ServiceAccount to an Okustera IAM role (okustera_iam_role), enabling Zero-Trust Pod Workload Identity where pods exchange projected OIDC tokens for temporary API Gateway STS session tokens without static secrets.
Example Usage
Bind Spark Worker Pods to IAM Role
resource "okustera_iam_role" "worker_role" {
name = "spark-worker-role"
namespace = "production"
s3_policy = {
enabled = true
buckets = ["spark-checkpoints"]
actions = ["*"]
}
}
resource "okustera_pod_identity_binding" "spark_binding" {
name = "spark-worker-binding"
namespace = "production"
service_account_name = "spark-worker-sa"
role_name = okustera_iam_role.worker_role.name
}
Schema
Required
name(String, Forces new resource) Unique name of the Pod identity binding.role_name(String) Name of theokustera_iam_roleto bind to.service_account_name(String) Name of the target KubernetesServiceAccount.
Optional
namespace(String, Forces new resource) Kubernetes namespace containing the ServiceAccount. Defaults todefault.role_namespace(String) Namespace of theokustera_iam_role(defaults to the binding namespace).
Read-Only
bound_at(String) Timestamp when identity binding was established.id(String) Combined binding identifier (<namespace>/<name>).
Import
Pod identity bindings can be imported using <namespace>/<name> or <name>:
terraform import okustera_pod_identity_binding.example "production/spark-worker-binding"