Blenra LogoBlenra
Optimized for: Gemini / ChatGPT / Claude
#Security

Advanced AI Prompt for AWS EKS Service Account (IRSA) Least-Privilege

Customize the variables below to instantly engineer your prompt.

Required Variables

advanced-ai-prompt-eks-irsa-iam-policy.txt
Act as a Kubernetes Security Engineer. Develop a highly specific IAM policy and an OIDC Trust Relationship designed for an AWS EKS Service Account utilizing IRSA (IAM Roles for Service Accounts). The execution policy must allow the pod to exclusively perform the `kms:Decrypt` action targeting only the specific KMS key [KMS_KEY_ARN]. The Trust Relationship JSON must strictly verify the cluster's OIDC provider [OIDC_PROVIDER_URL] and enforce a `StringEquals` condition ensuring the `sub` (subject) exactly matches `system:serviceaccount:[NAMESPACE]:[SERVICE_ACCOUNT_NAME]`. This guarantees no other service accounts in the cluster can maliciously assume this IAM role.

Example Text Output

"The AI provides a two-part JSON response: the scoped KMS IAM policy and the OIDC-verified trust policy for the IAM role."

More Cloud & DevOps Prompts

View all →

Frequently Asked Questions

What is the "Advanced AI Prompt for AWS EKS Service Account (IRSA) Least-Privilege" prompt used for?

The AI provides a two-part JSON response: the scoped KMS IAM policy and the OIDC-verified trust policy for the IAM role.

Which AI tools work with this prompt?

This prompt is optimized for Gemini / ChatGPT / Claude, but works great with ChatGPT, Claude, Gemini, and other large language models. Simply copy it and paste it into your preferred AI tool.

How do I customize this prompt?

Use the variable fields above to fill in your specific details. The prompt will auto-update as you type, ready to copy instantly.

Is this prompt free?

Yes! All prompts on Blenra are free to copy and use immediately. No account required.