Service account
By default the chart's pods run under the namespace's default service account and no ServiceAccount is created. Set serviceAccount.create: true to have the chart create one and bind the pods to it:
yaml
serviceAccount:
create: trueThe account is named after the release (<fullname>) unless you set serviceAccount.name. That name is also what the pods run as, so setting create: false with a name points the pods at a service account you manage elsewhere:
create | name | ServiceAccount created | Pods run as |
|---|---|---|---|
true | unset | yes, <fullname> | <fullname> |
true | myapp | yes, myapp | myapp |
false | unset | no | default |
false | myapp | no | myapp (must already exist) |
Annotations
serviceAccount.annotations land on the created account. This is where a cloud IAM binding goes, so a pod can assume a role without a static credential:
yaml
serviceAccount:
create: true
annotations:
eks.amazonaws.com/role-arn: arn:aws:iam::123456789012:role/myappThe global annotations value also reaches the account. See Annotations and the standard.serviceAccountName helper for the exact name resolution.