Blog|

Updates coming to cross-account role and permissions boundary for Enhanced Data Plane cluster management with Karpenter

1 min read |

Upcoming Astronomer Action: Required cross-account role updates

The upcoming policy changes include changes to both our cross account role policy and our operational boundary for service roles.

Operational boundary changes are required to allow the upcoming Karpenter-based node autoscaling controller to function. These changes are paired with changes to the cross account role policy to enable Astronomer to create and manage the requisite resources for the Karpenter controller as well as perform maintenance when needed. This includes SQS queues and EventBridge rule resources that are used for signalling node events to the Karpenter controller.

The bolded text is the addition.

Astronomer is also taking this opportunity to increase the reliability and support of Data Plane cluster management providing our automation and support team the means to address Istio ingress and RDS performance issues. The below permissions will be added as a result.

Thank you for your cooperation. If you have any questions, please log a ticket.

How to use an agent to manage your Airflow pipelinesOn September 29, we’re putting a data engineering agent to the test in a live session with Airflow experts. Join to see how it holds up against serious Airflow challenges, including upgrading from Airflow 2.x to 3, catching Airflow-specific issues, and everyday maintenance.Register now