# \[RESOLVED\] How can I get permission to access the EKS cluster from the AWS console?

**URL:** <https://community.convox.com/t/resolved-how-can-i-get-permission-to-access-the-eks-cluster-from-the-aws-console/828>\
**Category:** Rack (Version 3)\
**Created:** [September 17, 2021, 1:31am UTC](https://community.convox.com/t/resolved-how-can-i-get-permission-to-access-the-eks-cluster-from-the-aws-console/828 "2021-09-17T01:31:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nathan.f77](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.convox.com/nathan.f77/32/256_2.png) [@nathan.f77](https://community.convox.com/u/nathan.f77)\
**Post date:** [September 17, 2021, 1:31am UTC](https://community.convox.com/t/resolved-how-can-i-get-permission-to-access-the-eks-cluster-from-the-aws-console/828/1 "2021-09-17T01:31:02Z")

</div>

I’ve tried signing as the root user, and also a new user with the `AdministratorAccess` policy. I’m not able to view any Kubernetes objects with either of these users:

 ![Screen Shot 2021-09-17 at 1.23.37 PM](https://canada1.discourse-cdn.com/flex029/uploads/convox1/original/1X/3e38dc8dbdd4addf6cdc1db222a36bdbab6a0356.png)

The error says:

```auto
Your current user or role does not have access to Kubernetes objects on this EKS cluster

This may be due to the current user or role not having Kubernetes RBAC permissions to describe cluster resources or not having an entry in the cluster’s auth config map.

```

Link: [Troubleshooting IAM - Amazon EKS](https://docs.aws.amazon.com/eks/latest/userguide/troubleshooting_iam.html#security-iam-troubleshoot-cannot-view-nodes-or-workloads)

My IAM user needs this:

- Has a mapping to a Kubernetes user or group in the `aws-auth` configmap. For more information about adding IAM users or roles to the `aws-auth` configmap, see [Managing users or IAM roles for your cluster](https://docs.aws.amazon.com/eks/latest/userguide/add-user-role.html). If the user or role isn’t mapped, the console error may include **Unauthorized: Verify you have access to the Kubernetes cluster**

I found this file in convox/rack, which seems to set up `aws-auth` for k8s: [rack/cluster.yml.tmpl at 51bd19bdbe5905c146a0686e4f6c33dbf022a696 · convox/rack · GitHub](https://github.com/convox/rack/blob/51bd19bdbe5905c146a0686e4f6c33dbf022a696/provider/kaws/template/cluster.yml.tmpl)

```auto
apiVersion: v1
kind: ConfigMap
metadata:
  name: aws-auth
  namespace: kube-system
data:
  mapRoles: |
    - rolearn: {{.NodesRole}}
      username: system:node:{{"{{"}}EC2PrivateDNSName{{"}}"}}
      groups:
        - system:bootstrappers
        - system:nodes
  {{ with .AdminUser }}
  mapUsers: |
    - userarn: {{.}}
      username: admin
      groups:
        - system:masters
  {{ end }}

```

Another docs page: [Managing users or IAM roles for your cluster - Amazon EKS](https://docs.aws.amazon.com/eks/latest/userguide/add-user-role.html)

I’m a bit stuck now, and I also don’t know how to set up `kubectl` to access the k8s cluster. How can I fix my authentication so that I have permission to view EKS?

---

<div class="post-metadata">

**Author:** ![nathan.f77](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.convox.com/nathan.f77/32/256_2.png) [@nathan.f77](https://community.convox.com/u/nathan.f77)\
**Post date:** [September 17, 2021, 1:38am UTC](https://community.convox.com/t/resolved-how-can-i-get-permission-to-access-the-eks-cluster-from-the-aws-console/828/2 "2021-09-17T01:38:17Z")

</div>

I found the Direct Kubernetes Access page in the docs: [Convox Docs](https://docs.convox.com/management/direct-k8s-access)

The [Configure kubectl to Point at Your Rack](https://docs.convox.com/management/direct-k8s-access#configure-kubectl-to-point-at-your-rack) section was really helpful, so thanks for this!

These instructions worked, and now I can view namespaces and pods, etc.:

```auto
$ kubectl get namespace
NAME STATUS AGE
cert-manager Active 3h5m
default Active 3h11m
ds-test3-myapp Active 3h
ds-test3-system Active 3h5m
kube-node-lease Active 3h11m
kube-public Active 3h11m
kube-system Active 3h11m

$ kubectl get pods --namespace=ds-test3-myapp
NAME READY STATUS RESTARTS AGE
resource-database-7b9cb5ddb5-vznrb 1/1 Running 0 25m
resource-redis-5fc7577b9d-h52tv 1/1 Running 0 25m
web-97898fd59-72n7c 1/1 Running 0 36m
web-97898fd59-dvcxm 1/1 Running 0 36m
web-97898fd59-j2dlp 1/1 Running 0 14m
web-97898fd59-vv77m 1/1 Running 0 15m
worker-84c997fb55-2mmxs 1/1 Running 0 14m
worker-84c997fb55-wczpb 1/1 Running 0 25m
worker-84c997fb55-zfx85 1/1 Running 0 36m

```

---

<div class="post-metadata">

**Author:** ![nathan.f77](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.convox.com/nathan.f77/32/256_2.png) [@nathan.f77](https://community.convox.com/u/nathan.f77)\
**Post date:** [September 17, 2021, 1:48am UTC](https://community.convox.com/t/resolved-how-can-i-get-permission-to-access-the-eks-cluster-from-the-aws-console/828/3 "2021-09-17T01:48:15Z")

</div>

Woohoo, I figured it out!

After I got `kubectl` working, I could follow the “To add an IAM user or role to an Amazon EKS cluster” instructions on this page: [Managing users or IAM roles for your cluster - Amazon EKS](https://docs.aws.amazon.com/eks/latest/userguide/add-user-role.html)

Tip: Run `export KUBE_EDITOR=vim` to edit the config in vim.

```auto
$ export KUBE_EDITOR=vim
$ kubectl edit -n kube-system configmap/aws-auth

```

This opened vim with the k8s auth config. I added the `mapUsers` section to add an “admin” user to the `system:masters` group:

```auto
# Please edit the object below. Lines beginning with a '#' will be ignored,
# and an empty file will abort the edit. If an error occurs while saving this file will be
# reopened with the relevant failures.
#
apiVersion: v1
data:
  mapRoles: |
    - groups:
      - system:bootstrappers
      - system:nodes
      rolearn: arn:aws:iam::1234123412341234:role/ds-test3-nodes
      username: system:node:{{EC2PrivateDNSName}}
  mapUsers: |
    - userarn: arn:aws:iam::1234123412341234:user/nathan
      username: admin
      groups:
        - system:masters
kind: ConfigMap
metadata:
  creationTimestamp: "2021-09-16T22:30:37Z"
  name: aws-auth
  namespace: kube-system
  resourceVersion: "859"
  selfLink: /api/v1/namespaces/kube-system/configmaps/aws-auth
  uid: *****

```

After I saved the file and quit vim, I was able to view the k8s resources for the EKS cluster:

 ![Screen Shot 2021-09-17 at 1.46.45 PM](https://canada1.discourse-cdn.com/flex029/uploads/convox1/original/1X/4046aa21b1493cd2f7fe7db2136f709fe7ffb04b.png)
