Containers-roadmap: New EKS Region : Ningxia

Created on 20 Dec 2018  路  24Comments  路  Source: aws/containers-roadmap

Tell us about your request
New region support in Ningxia, China(cn-northwest-1)

Which service(s) is this request for?
Amazon EKS

Please add the support plan in the roadmap. Thanks.

EKS

Most helpful comment

Happy to announce that EKS is now generally available in the AWS Ningxia (cn-northwest-1) region!

All 24 comments

+1

Is there a timeline associated with this yet?

We're ready to jump on testing it as soon as the preview is available.

馃憤 Same here, eagerly awaiting developer preview

still coming soon?

At what stage is it currently?

when is EKS ready in aws china? is there a time line?

Any updates on this?

Any update?

Any updates on this?

Any updates on this ?

Any updates on this ?

Any updates on this ?

This must be close now! :) Any news?

Just Shipped

Happy to announce that EKS is now generally available in the AWS Ningxia (cn-northwest-1) region!

Thanks to you and the team for all the hard work @mikestef9

What's the service Principal name?

An error occurred: Invalid principal in policy: "SERVICE":"eks.amazonaws.cn"

If I try to create a test cluster in Ningxia, with a role that I know exists I get this error.

Role with $existing_role_arn, could not be assumed because it does not exist or the trusted entity is not correct

@groodt is the IAM role created in a China region? You can't use a non China IAM role in a China region

Yup, the role is in China.

Our role is in China.

ARN looks as follows:

arn: arn:aws-cn:iam::${accountid}:role/${rolename}

Trust relationship looks as follows:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "",
      "Effect": "Allow",
      "Principal": {
        "Service": "eks.amazonaws.com"
      },
      "Action": "sts:AssumeRole"
    }
  ]
}

The role has the following managed policies attached:

AmazonEKSServicePolicy

Hi @groodt would recommend you open a support ticket to further troubleshoot

Found the issue. We have a permission boundary on the role and needed to allow:

iam:ListAttachedRolePolicies

Works now! Apologies for any noise.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

yavor-atanasov picture yavor-atanasov  路  3Comments

pauldougan picture pauldougan  路  3Comments

chungath picture chungath  路  3Comments

sarath9985 picture sarath9985  路  3Comments

tabern picture tabern  路  3Comments