<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Setup federation for CSP's on</title><link>/kosmos/fleets/csp-account-federation/</link><description>Recent content in Setup federation for CSP's on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><atom:link href="/kosmos/fleets/csp-account-federation/index.xml" rel="self" type="application/rss+xml"/><item><title>Setup Federation for AWS</title><link>/kosmos/fleets/csp-account-federation/setup-federation-for-aws/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/kosmos/fleets/csp-account-federation/setup-federation-for-aws/</guid><description>This module provisions IAM resources in AWS for Kosmos to authenticate via OIDC and create EKS clusters. It includes:
An IAM Role for Kosmos with a Trust Policy defining who can assume the role. A Permissions Policy granting Kosmos the necessary permissions to create an EKS cluster. Policy Attachment linking the permissions policy to the IAM role. (Optional) An OIDC Provider Entry in AWS, representing Kosmos as an OIDC provider.</description></item><item><title>Setup Federation for Azure</title><link>/kosmos/fleets/csp-account-federation/setup-federation-for-azure/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/kosmos/fleets/csp-account-federation/setup-federation-for-azure/</guid><description>This module provisions identity resources in Azure for Kosmos to authenticate via OIDC and create AKS clusters. It includes:
A Service Principal and an extra application for Kosmos to use in AKS cluster creation. Roles and Role Assignments granting the service principal necessary permissions for AKS cluster creation. OIDC Provider Entry for Kosmos authentication. Variables # Required Variables # Variable Description resource_group_name Name of the Azure resource group where the AKS cluster will be created.</description></item><item><title>Setup Federation for GCP</title><link>/kosmos/fleets/csp-account-federation/setup-federation-for-gcp/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/kosmos/fleets/csp-account-federation/setup-federation-for-gcp/</guid><description>This module provisions IAM resources in GCP for Kosmos to authenticate via OIDC and create GKE clusters. It includes:
A Service Account for Kosmos to impersonate using its OIDC token. The required IAM roles attached to the service account. (Optional) A Workload Identity Pool and Provider if an existing one does not exist. Variables # Required Variables # Variable Description oidc_issuer_uri (Required) Issuer URL of the OIDC provider for creating the workload identity provider in GCP.</description></item><item><title>Setup Federation for SPC</title><link>/kosmos/fleets/csp-account-federation/setup-federation-for-spc/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/kosmos/fleets/csp-account-federation/setup-federation-for-spc/</guid><description>Overview # This module provisions IAM resources for Kosmos to create and manage EKS clusters using OIDC authentication. It includes:
An IAM Role for Kosmos with an associated Trust Policy to define who can assume the role. A Permissions Policy granting Kosmos the necessary permissions to create EKS clusters. An Attachment linking the permission policy to the IAM role. (Optional) Creation of an OIDC Provider entry in SPC for Kosmos.</description></item></channel></rss>