KOP EKS Clusters - Identity Mapping - Rafay Product Documentation

Identity Mapping

Identity Mapping

Post cluster provisioning, the Identity Mapping feature helps the users to create a static mapping between IAM Users and Roles, and Kubernetes RBAC groups. This allows users/roles to access specified EKS cluster resources in AWS Console.


Create IAM Mapping

Below is an example of both USER and ROLE IAM Mapping

Once the mapping is successful, you can view the ARNs in the table as shown below

Now the users can access the cluster resources via AWS Console

To add IAM Mappings during cluster provisioning, refer IAM Mapping CLI

Delete IAM Mapping


Accounts

Accounts tab allows the users to add one or more accounts. This helps to provide access to clusters available in different accounts

Once the accounts are added, you can view the newly added accounts in the table as shown below

The arn of respective accounts are used to create an IAM Mapping

Use the delete icon to delete one or more account(s)