docs(aws): add Route53 and Kubernetes IAM policies #1

Open
anton wants to merge 1 commit from import-dns-policy into main
Owner

Summary

  • Add aws/iam/route53.json, unchanged from the operator-supplied policy.
  • Add aws/iam/kubernetes.json, preserving the supplied policy and adding backup-object access under velero/* and barman/*, hosted-zone discovery, and DNS change-status reads.

Only these two JSON files are included, in one commit. No README or test-file changes.

These are reference/proposed policies, not Terraform-managed resources. Nothing was applied to AWS. Existing broad administrative permissions are preserved; live attachments and effective permissions remain unverified.

Verification

Ad-hoc checks passed for JSON validity, exact added action/resource scopes, unchanged policy contents, the two-file-only diff, and whitespace.

## Summary - Add `aws/iam/route53.json`, unchanged from the operator-supplied policy. - Add `aws/iam/kubernetes.json`, preserving the supplied policy and adding backup-object access under `velero/*` and `barman/*`, hosted-zone discovery, and DNS change-status reads. Only these two JSON files are included, in one commit. No README or test-file changes. These are reference/proposed policies, not Terraform-managed resources. Nothing was applied to AWS. Existing broad administrative permissions are preserved; live attachments and effective permissions remain unverified. ## Verification Ad-hoc checks passed for JSON validity, exact added action/resource scopes, unchanged policy contents, the two-file-only diff, and whitespace.
anton changed title from docs(aws): record Route53 IAM policy and controller scope to docs(aws): record DNS policy and Kubernetes permission fixes 2026-10-02 23:55:03 +00:00
anton force-pushed import-dns-policy from 8815012ae7 to be60359b7f 2026-10-03 00:04:42 +00:00 Compare
anton changed title from docs(aws): record DNS policy and Kubernetes permission fixes to docs(aws): add Route53 and Kubernetes IAM policies 2026-10-03 00:04:43 +00:00
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin import-dns-policy:import-dns-policy
git switch import-dns-policy

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff import-dns-policy
git switch import-dns-policy
git rebase main
git switch main
git merge --ff-only import-dns-policy
git switch import-dns-policy
git rebase main
git switch main
git merge --no-ff import-dns-policy
git switch main
git merge --squash import-dns-policy
git switch main
git merge --ff-only import-dns-policy
git switch main
git merge import-dns-policy
git push origin main
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
public/infrastructure!1
No description provided.