EKS NodeGroup - The aws-auth ConfigMap in your cluster is invalid
I've got an issue with an EKS node group where I cannot delete it.
I've provisioned the EKS cluster with Terraform and configured aws-auth as per documentation below:
I've admin access to the cluster, I also have deployments running and worker nodes connected. My ConfigMap can be seen below:
$ kubectl describe configmap -n kube-system aws-auth
- rolearn: arn:aws:iam::000000000000:role/cluster-role
- rolearn: arn:aws:iam::000000000000:role/node-group-role
- rolearn: arn:aws:iam::000000000000:role/aws-reserved/sso.amazonaws.com/eu-west-2/AWSReservedSSO_AdministratorAccess
When I attempt to delete the node group, either via Terraform or using AWS Console, I get the following error listed under Health Issues:
"AccessDenied The aws-auth ConfigMap in your cluster is invalid."
I did not get this error when I created the node group, and I can't work out what exactly is wrong with my ConfigMap.
I've resolved the problem by deleting the aws-auth ConfigMap from the kube-system namespace. This allowed me to delete the node group from the cluster.
Note that when you create an EKS cluster, the IAM entity user that creates the cluster is automatically granted system:masters permissions in the cluster's RBAC configuration in the control plane. This IAM entity does not appear in the ConfigMap, but can be used to get access to the cluster.
Cannot delete because cluster <cluster name> currently has an update in progressAccepted Answerasked 3 months ago
Problem adding nodegroup in EKS cluster with GW NATasked a month ago
EKS issue when adding node group with t4g class instanceasked 5 months ago
How to create EKS cluster with dedicated host node groupAccepted Answerasked 6 months ago
EKS NodeGroup IAM Role on Config File (yaml)Accepted Answerasked a month ago
EKS NodeGroup - The aws-auth ConfigMap in your cluster is invalidasked a year ago
EKS Cluster Create FailedAccepted Answerasked 4 months ago
Unable to create EKS Clusterasked a month ago
EKS Node Group with RIAccepted AnswerEXPERTasked 2 years ago
EKS Cluster stuck in updatingasked 2 months ago