1
0
mirror of https://github.com/terraform-aws-modules/terraform-aws-eks.git synced 2025-09-09 19:32:58 +08:00

feat!: Upgrade min AWS provider and Terraform versions to 6.0 and 1.5.7 respectively (#3412)

* feat!: Upgrade min AWS provider and Terraform versions to `6.0` and `1.5.7` respectively

* fix: Remove deprecated arguments in AWS v6.0 provider, upgrade Helm provider to v3.0, bump VPC module to v6.0

* fix: Remove `aws-auth` sub-module

* fix: Remove `platform` and `cluster_service_ipv4_cidr` variables from `user-data` sub-module

* fix: Resolve all marked `todos` that have been accumulated

* fix: Set default `http_put_response_hop_limit` to `1`

* fix: Remove IRSA support from Karpenter sub-module

* fix: Avoid making GET requests from data sources unless absolutely necessary

* feat: Add variable optional attribute definitions

* feat: Bump KMS key module version to latest, add remaining variable attribute definitions

* fix: Remove `cluster_` prefix from variable names to better match the underlying API

* fix: Move all EFA logic to the nodegroup itself

* fix: Remove arguments that do not make sense in EKS

* fix: Updates from plan validation

* fix: Remove more self-managed node group attributes that are commonly not used in EKS clusters

* fix: Remove data plane compute `*_defaults` variables that do not work with variable optional attributes

* fix: Ignore changes to `bootstrap_self_managed_addons` to aid in upgrade

* feat: Add support for `region` argument on relevant resources

* feat: Initial pass on upgrade guide

* fix: Updates from testing and validating EKS managed node group

* fix: Updates from testing and validating self-managed node group

* docs: Ensure addon ussage documented is aligned

* feat: Switch to dualstack OIDC issuer URL

* feat: Allow sourcing over overriding the Karpenter assume role policy

* fix: Use `Bool` instead of `StringEquals` for DenyHTTP queue policy

* fix: Correct use of `nullable` and default value propagation
This commit is contained in:
Bryant Biggs
2025-07-23 15:11:01 -05:00
committed by GitHub
parent 8a0efdbbc8
commit 416515a0da
84 changed files with 4111 additions and 3339 deletions
+267 -300
View File
@@ -1,23 +1,4 @@
locals {
metadata_options = {
http_endpoint = "enabled"
http_tokens = "required"
http_put_response_hop_limit = 2
}
# EKS managed node group
default_update_config = {
max_unavailable_percentage = 33
}
# Self-managed node group
default_instance_refresh = {
strategy = "Rolling"
preferences = {
min_healthy_percentage = 66
}
}
kubernetes_network_config = try(aws_eks_cluster.this[0].kubernetes_network_config[0], {})
}
@@ -32,12 +13,12 @@ resource "time_sleep" "this" {
create_duration = var.dataplane_wait_duration
triggers = {
cluster_name = aws_eks_cluster.this[0].id
cluster_endpoint = aws_eks_cluster.this[0].endpoint
cluster_version = aws_eks_cluster.this[0].version
cluster_service_cidr = var.cluster_ip_family == "ipv6" ? try(local.kubernetes_network_config.service_ipv6_cidr, "") : try(local.kubernetes_network_config.service_ipv4_cidr, "")
name = aws_eks_cluster.this[0].id
endpoint = aws_eks_cluster.this[0].endpoint
kubernetes_version = aws_eks_cluster.this[0].version
service_cidr = var.ip_family == "ipv6" ? try(local.kubernetes_network_config.service_ipv6_cidr, "") : try(local.kubernetes_network_config.service_ipv4_cidr, "")
cluster_certificate_authority_data = aws_eks_cluster.this[0].certificate_authority[0].data
certificate_authority_data = aws_eks_cluster.this[0].certificate_authority[0].data
}
}
@@ -87,7 +68,7 @@ resource "aws_iam_policy" "cni_ipv6_policy" {
################################################################################
locals {
node_sg_name = coalesce(var.node_security_group_name, "${var.cluster_name}-node")
node_sg_name = coalesce(var.node_security_group_name, "${var.name}-node")
create_node_sg = var.create && var.create_node_security_group
node_security_group_id = local.create_node_sg ? aws_security_group.node[0].id : var.node_security_group_id
@@ -179,35 +160,16 @@ locals {
to_port = 0
type = "egress"
cidr_blocks = ["0.0.0.0/0"]
ipv6_cidr_blocks = var.cluster_ip_family == "ipv6" ? ["::/0"] : null
ipv6_cidr_blocks = var.ip_family == "ipv6" ? ["::/0"] : null
}
} : k => v if var.node_security_group_enable_recommended_rules }
efa_security_group_rules = { for k, v in
{
ingress_all_self_efa = {
description = "Node to node EFA"
protocol = "-1"
from_port = 0
to_port = 0
type = "ingress"
self = true
}
egress_all_self_efa = {
description = "Node to node EFA"
protocol = "-1"
from_port = 0
to_port = 0
type = "egress"
self = true
}
} : k => v if var.enable_efa_support
}
}
resource "aws_security_group" "node" {
count = local.create_node_sg ? 1 : 0
region = var.region
name = var.node_security_group_use_name_prefix ? null : local.node_sg_name
name_prefix = var.node_security_group_use_name_prefix ? "${local.node_sg_name}${var.prefix_separator}" : null
description = var.node_security_group_description
@@ -216,8 +178,8 @@ resource "aws_security_group" "node" {
tags = merge(
var.tags,
{
"Name" = local.node_sg_name
"kubernetes.io/cluster/${var.cluster_name}" = "owned"
"Name" = local.node_sg_name
"kubernetes.io/cluster/${var.name}" = "owned"
},
var.node_security_group_tags
)
@@ -229,26 +191,24 @@ resource "aws_security_group" "node" {
resource "aws_security_group_rule" "node" {
for_each = { for k, v in merge(
local.efa_security_group_rules,
local.node_security_group_rules,
local.node_security_group_recommended_rules,
var.node_security_group_additional_rules,
) : k => v if local.create_node_sg }
# Required
security_group_id = aws_security_group.node[0].id
protocol = each.value.protocol
from_port = each.value.from_port
to_port = each.value.to_port
type = each.value.type
region = var.region
# Optional
description = lookup(each.value, "description", null)
cidr_blocks = lookup(each.value, "cidr_blocks", null)
ipv6_cidr_blocks = lookup(each.value, "ipv6_cidr_blocks", null)
prefix_list_ids = lookup(each.value, "prefix_list_ids", [])
self = lookup(each.value, "self", null)
source_security_group_id = try(each.value.source_cluster_security_group, false) ? local.cluster_security_group_id : lookup(each.value, "source_security_group_id", null)
security_group_id = aws_security_group.node[0].id
protocol = each.value.protocol
from_port = each.value.from_port
to_port = each.value.to_port
type = each.value.type
description = try(each.value.description, null)
cidr_blocks = try(each.value.cidr_blocks, null)
ipv6_cidr_blocks = try(each.value.ipv6_cidr_blocks, null)
prefix_list_ids = try(each.value.prefix_list_ids, null)
self = try(each.value.self, null)
source_security_group_id = try(each.value.source_cluster_security_group, false) ? local.security_group_id : try(each.value.source_security_group_id, null)
}
################################################################################
@@ -258,35 +218,42 @@ resource "aws_security_group_rule" "node" {
module "fargate_profile" {
source = "./modules/fargate-profile"
for_each = { for k, v in var.fargate_profiles : k => v if var.create && !local.create_outposts_local_cluster }
for_each = var.create && !local.create_outposts_local_cluster && var.fargate_profiles != null ? var.fargate_profiles : {}
create = try(each.value.create, true)
create = each.value.create
region = var.region
# Pass through values to reduce GET requests from data sources
partition = local.partition
account_id = local.account_id
# Fargate Profile
cluster_name = time_sleep.this[0].triggers["cluster_name"]
cluster_ip_family = var.cluster_ip_family
name = try(each.value.name, each.key)
subnet_ids = try(each.value.subnet_ids, var.fargate_profile_defaults.subnet_ids, var.subnet_ids)
selectors = try(each.value.selectors, var.fargate_profile_defaults.selectors, [])
timeouts = try(each.value.timeouts, var.fargate_profile_defaults.timeouts, {})
cluster_name = time_sleep.this[0].triggers["name"]
cluster_ip_family = var.ip_family
name = coalesce(each.value.name, each.key)
subnet_ids = coalesce(each.value.subnet_ids, var.subnet_ids)
selectors = each.value.selectors
timeouts = each.value.timeouts
# IAM role
create_iam_role = try(each.value.create_iam_role, var.fargate_profile_defaults.create_iam_role, true)
iam_role_arn = try(each.value.iam_role_arn, var.fargate_profile_defaults.iam_role_arn, null)
iam_role_name = try(each.value.iam_role_name, var.fargate_profile_defaults.iam_role_name, null)
iam_role_use_name_prefix = try(each.value.iam_role_use_name_prefix, var.fargate_profile_defaults.iam_role_use_name_prefix, true)
iam_role_path = try(each.value.iam_role_path, var.fargate_profile_defaults.iam_role_path, null)
iam_role_description = try(each.value.iam_role_description, var.fargate_profile_defaults.iam_role_description, "Fargate profile IAM role")
iam_role_permissions_boundary = try(each.value.iam_role_permissions_boundary, var.fargate_profile_defaults.iam_role_permissions_boundary, null)
iam_role_tags = try(each.value.iam_role_tags, var.fargate_profile_defaults.iam_role_tags, {})
iam_role_attach_cni_policy = try(each.value.iam_role_attach_cni_policy, var.fargate_profile_defaults.iam_role_attach_cni_policy, true)
# To better understand why this `lookup()` logic is required, see:
# https://github.com/hashicorp/terraform/issues/31646#issuecomment-1217279031
iam_role_additional_policies = lookup(each.value, "iam_role_additional_policies", lookup(var.fargate_profile_defaults, "iam_role_additional_policies", {}))
create_iam_role_policy = try(each.value.create_iam_role_policy, var.fargate_profile_defaults.create_iam_role_policy, true)
iam_role_policy_statements = try(each.value.iam_role_policy_statements, var.fargate_profile_defaults.iam_role_policy_statements, [])
create_iam_role = each.value.create_iam_role
iam_role_arn = each.value.iam_role_arn
iam_role_name = each.value.iam_role_name
iam_role_use_name_prefix = each.value.iam_role_use_name_prefix
iam_role_path = each.value.iam_role_path
iam_role_description = each.value.iam_role_description
iam_role_permissions_boundary = each.value.iam_role_permissions_boundary
iam_role_tags = each.value.iam_role_tags
iam_role_attach_cni_policy = each.value.iam_role_attach_cni_policy
iam_role_additional_policies = lookup(each.value, "iam_role_additional_policies", null)
create_iam_role_policy = each.value.create_iam_role_policy
iam_role_policy_statements = each.value.iam_role_policy_statements
tags = merge(var.tags, try(each.value.tags, var.fargate_profile_defaults.tags, {}))
tags = merge(
var.tags,
each.value.tags,
)
}
################################################################################
@@ -296,120 +263,124 @@ module "fargate_profile" {
module "eks_managed_node_group" {
source = "./modules/eks-managed-node-group"
for_each = { for k, v in var.eks_managed_node_groups : k => v if var.create && !local.create_outposts_local_cluster }
for_each = var.create && !local.create_outposts_local_cluster && var.eks_managed_node_groups != null ? var.eks_managed_node_groups : {}
create = try(each.value.create, true)
create = each.value.create
cluster_name = time_sleep.this[0].triggers["cluster_name"]
cluster_version = try(each.value.cluster_version, var.eks_managed_node_group_defaults.cluster_version, time_sleep.this[0].triggers["cluster_version"])
region = var.region
# Pass through values to reduce GET requests from data sources
partition = local.partition
account_id = local.account_id
cluster_name = time_sleep.this[0].triggers["name"]
kubernetes_version = try(each.value.kubernetes_version, time_sleep.this[0].triggers["kubernetes_version"])
# EKS Managed Node Group
name = try(each.value.name, each.key)
use_name_prefix = try(each.value.use_name_prefix, var.eks_managed_node_group_defaults.use_name_prefix, true)
name = coalesce(each.value.name, each.key)
use_name_prefix = each.value.use_name_prefix
subnet_ids = try(each.value.subnet_ids, var.eks_managed_node_group_defaults.subnet_ids, var.subnet_ids)
subnet_ids = coalesce(each.value.subnet_ids, var.subnet_ids)
min_size = try(each.value.min_size, var.eks_managed_node_group_defaults.min_size, 1)
max_size = try(each.value.max_size, var.eks_managed_node_group_defaults.max_size, 3)
desired_size = try(each.value.desired_size, var.eks_managed_node_group_defaults.desired_size, 1)
min_size = each.value.min_size
max_size = each.value.max_size
desired_size = each.value.desired_size
ami_id = try(each.value.ami_id, var.eks_managed_node_group_defaults.ami_id, "")
ami_type = try(each.value.ami_type, var.eks_managed_node_group_defaults.ami_type, null)
ami_release_version = try(each.value.ami_release_version, var.eks_managed_node_group_defaults.ami_release_version, null)
use_latest_ami_release_version = try(each.value.use_latest_ami_release_version, var.eks_managed_node_group_defaults.use_latest_ami_release_version, false)
ami_id = each.value.ami_id
ami_type = each.value.ami_type
ami_release_version = each.value.ami_release_version
use_latest_ami_release_version = each.value.use_latest_ami_release_version
capacity_type = try(each.value.capacity_type, var.eks_managed_node_group_defaults.capacity_type, null)
disk_size = try(each.value.disk_size, var.eks_managed_node_group_defaults.disk_size, null)
force_update_version = try(each.value.force_update_version, var.eks_managed_node_group_defaults.force_update_version, null)
instance_types = try(each.value.instance_types, var.eks_managed_node_group_defaults.instance_types, null)
labels = try(each.value.labels, var.eks_managed_node_group_defaults.labels, null)
node_repair_config = try(each.value.node_repair_config, var.eks_managed_node_group_defaults.node_repair_config, null)
remote_access = try(each.value.remote_access, var.eks_managed_node_group_defaults.remote_access, {})
taints = try(each.value.taints, var.eks_managed_node_group_defaults.taints, {})
update_config = try(each.value.update_config, var.eks_managed_node_group_defaults.update_config, local.default_update_config)
timeouts = try(each.value.timeouts, var.eks_managed_node_group_defaults.timeouts, {})
capacity_type = each.value.capacity_type
disk_size = each.value.disk_size
force_update_version = each.value.force_update_version
instance_types = each.value.instance_types
labels = each.value.labels
node_repair_config = each.value.node_repair_config
remote_access = each.value.remote_access
taints = each.value.taints
update_config = each.value.update_config
timeouts = each.value.timeouts
# User data
platform = try(each.value.platform, var.eks_managed_node_group_defaults.platform, "linux")
cluster_endpoint = try(time_sleep.this[0].triggers["cluster_endpoint"], "")
cluster_auth_base64 = try(time_sleep.this[0].triggers["cluster_certificate_authority_data"], "")
cluster_service_ipv4_cidr = var.cluster_service_ipv4_cidr
cluster_ip_family = var.cluster_ip_family
cluster_service_cidr = try(time_sleep.this[0].triggers["cluster_service_cidr"], "")
enable_bootstrap_user_data = try(each.value.enable_bootstrap_user_data, var.eks_managed_node_group_defaults.enable_bootstrap_user_data, false)
pre_bootstrap_user_data = try(each.value.pre_bootstrap_user_data, var.eks_managed_node_group_defaults.pre_bootstrap_user_data, "")
post_bootstrap_user_data = try(each.value.post_bootstrap_user_data, var.eks_managed_node_group_defaults.post_bootstrap_user_data, "")
bootstrap_extra_args = try(each.value.bootstrap_extra_args, var.eks_managed_node_group_defaults.bootstrap_extra_args, "")
user_data_template_path = try(each.value.user_data_template_path, var.eks_managed_node_group_defaults.user_data_template_path, "")
cloudinit_pre_nodeadm = try(each.value.cloudinit_pre_nodeadm, var.eks_managed_node_group_defaults.cloudinit_pre_nodeadm, [])
cloudinit_post_nodeadm = try(each.value.cloudinit_post_nodeadm, var.eks_managed_node_group_defaults.cloudinit_post_nodeadm, [])
cluster_endpoint = try(time_sleep.this[0].triggers["endpoint"], "")
cluster_auth_base64 = try(time_sleep.this[0].triggers["certificate_authority_data"], "")
cluster_ip_family = var.ip_family
cluster_service_cidr = try(time_sleep.this[0].triggers["service_cidr"], "")
enable_bootstrap_user_data = each.value.enable_bootstrap_user_data
pre_bootstrap_user_data = each.value.pre_bootstrap_user_data
post_bootstrap_user_data = each.value.post_bootstrap_user_data
bootstrap_extra_args = each.value.bootstrap_extra_args
user_data_template_path = each.value.user_data_template_path
cloudinit_pre_nodeadm = each.value.cloudinit_pre_nodeadm
cloudinit_post_nodeadm = each.value.cloudinit_post_nodeadm
# Launch Template
create_launch_template = try(each.value.create_launch_template, var.eks_managed_node_group_defaults.create_launch_template, true)
use_custom_launch_template = try(each.value.use_custom_launch_template, var.eks_managed_node_group_defaults.use_custom_launch_template, true)
launch_template_id = try(each.value.launch_template_id, var.eks_managed_node_group_defaults.launch_template_id, "")
launch_template_name = try(each.value.launch_template_name, var.eks_managed_node_group_defaults.launch_template_name, each.key)
launch_template_use_name_prefix = try(each.value.launch_template_use_name_prefix, var.eks_managed_node_group_defaults.launch_template_use_name_prefix, true)
launch_template_version = try(each.value.launch_template_version, var.eks_managed_node_group_defaults.launch_template_version, null)
launch_template_default_version = try(each.value.launch_template_default_version, var.eks_managed_node_group_defaults.launch_template_default_version, null)
update_launch_template_default_version = try(each.value.update_launch_template_default_version, var.eks_managed_node_group_defaults.update_launch_template_default_version, true)
launch_template_description = try(each.value.launch_template_description, var.eks_managed_node_group_defaults.launch_template_description, "Custom launch template for ${try(each.value.name, each.key)} EKS managed node group")
launch_template_tags = try(each.value.launch_template_tags, var.eks_managed_node_group_defaults.launch_template_tags, {})
tag_specifications = try(each.value.tag_specifications, var.eks_managed_node_group_defaults.tag_specifications, ["instance", "volume", "network-interface"])
create_launch_template = each.value.create_launch_template
use_custom_launch_template = each.value.use_custom_launch_template
launch_template_id = each.value.launch_template_id
launch_template_name = coalesce(each.value.launch_template_name, each.key)
launch_template_use_name_prefix = each.value.launch_template_use_name_prefix
launch_template_version = each.value.launch_template_version
launch_template_default_version = each.value.launch_template_default_version
update_launch_template_default_version = each.value.update_launch_template_default_version
launch_template_description = coalesce(each.value.launch_template_description, "Custom launch template for ${coalesce(each.value.name, each.key)} EKS managed node group")
launch_template_tags = each.value.launch_template_tags
tag_specifications = each.value.tag_specifications
ebs_optimized = try(each.value.ebs_optimized, var.eks_managed_node_group_defaults.ebs_optimized, null)
key_name = try(each.value.key_name, var.eks_managed_node_group_defaults.key_name, null)
disable_api_termination = try(each.value.disable_api_termination, var.eks_managed_node_group_defaults.disable_api_termination, null)
kernel_id = try(each.value.kernel_id, var.eks_managed_node_group_defaults.kernel_id, null)
ram_disk_id = try(each.value.ram_disk_id, var.eks_managed_node_group_defaults.ram_disk_id, null)
ebs_optimized = each.value.ebs_optimized
key_name = each.value.key_name
disable_api_termination = each.value.disable_api_termination
kernel_id = each.value.kernel_id
ram_disk_id = each.value.ram_disk_id
block_device_mappings = try(each.value.block_device_mappings, var.eks_managed_node_group_defaults.block_device_mappings, {})
capacity_reservation_specification = try(each.value.capacity_reservation_specification, var.eks_managed_node_group_defaults.capacity_reservation_specification, {})
cpu_options = try(each.value.cpu_options, var.eks_managed_node_group_defaults.cpu_options, {})
credit_specification = try(each.value.credit_specification, var.eks_managed_node_group_defaults.credit_specification, {})
elastic_gpu_specifications = try(each.value.elastic_gpu_specifications, var.eks_managed_node_group_defaults.elastic_gpu_specifications, {})
elastic_inference_accelerator = try(each.value.elastic_inference_accelerator, var.eks_managed_node_group_defaults.elastic_inference_accelerator, {})
enclave_options = try(each.value.enclave_options, var.eks_managed_node_group_defaults.enclave_options, {})
instance_market_options = try(each.value.instance_market_options, var.eks_managed_node_group_defaults.instance_market_options, {})
license_specifications = try(each.value.license_specifications, var.eks_managed_node_group_defaults.license_specifications, {})
metadata_options = try(each.value.metadata_options, var.eks_managed_node_group_defaults.metadata_options, local.metadata_options)
enable_monitoring = try(each.value.enable_monitoring, var.eks_managed_node_group_defaults.enable_monitoring, true)
enable_efa_support = try(each.value.enable_efa_support, var.eks_managed_node_group_defaults.enable_efa_support, false)
enable_efa_only = try(each.value.enable_efa_only, var.eks_managed_node_group_defaults.enable_efa_only, false)
efa_indices = try(each.value.efa_indices, var.eks_managed_node_group_defaults.efa_indices, [0])
create_placement_group = try(each.value.create_placement_group, var.eks_managed_node_group_defaults.create_placement_group, false)
placement = try(each.value.placement, var.eks_managed_node_group_defaults.placement, {})
placement_group_az = try(each.value.placement_group_az, var.eks_managed_node_group_defaults.placement_group_az, null)
placement_group_strategy = try(each.value.placement_group_strategy, var.eks_managed_node_group_defaults.placement_group_strategy, "cluster")
network_interfaces = try(each.value.network_interfaces, var.eks_managed_node_group_defaults.network_interfaces, [])
maintenance_options = try(each.value.maintenance_options, var.eks_managed_node_group_defaults.maintenance_options, {})
private_dns_name_options = try(each.value.private_dns_name_options, var.eks_managed_node_group_defaults.private_dns_name_options, {})
block_device_mappings = each.value.block_device_mappings
capacity_reservation_specification = each.value.capacity_reservation_specification
cpu_options = each.value.cpu_options
credit_specification = each.value.credit_specification
enclave_options = each.value.enclave_options
instance_market_options = each.value.instance_market_options
license_specifications = each.value.license_specifications
metadata_options = each.value.metadata_options
enable_monitoring = each.value.enable_monitoring
enable_efa_support = each.value.enable_efa_support
enable_efa_only = each.value.enable_efa_only
efa_indices = each.value.efa_indices
create_placement_group = each.value.create_placement_group
placement = each.value.placement
network_interfaces = each.value.network_interfaces
maintenance_options = each.value.maintenance_options
private_dns_name_options = each.value.private_dns_name_options
# IAM role
create_iam_role = try(each.value.create_iam_role, var.eks_managed_node_group_defaults.create_iam_role, true)
iam_role_arn = try(each.value.iam_role_arn, var.eks_managed_node_group_defaults.iam_role_arn, null)
iam_role_name = try(each.value.iam_role_name, var.eks_managed_node_group_defaults.iam_role_name, null)
iam_role_use_name_prefix = try(each.value.iam_role_use_name_prefix, var.eks_managed_node_group_defaults.iam_role_use_name_prefix, true)
iam_role_path = try(each.value.iam_role_path, var.eks_managed_node_group_defaults.iam_role_path, null)
iam_role_description = try(each.value.iam_role_description, var.eks_managed_node_group_defaults.iam_role_description, "EKS managed node group IAM role")
iam_role_permissions_boundary = try(each.value.iam_role_permissions_boundary, var.eks_managed_node_group_defaults.iam_role_permissions_boundary, null)
iam_role_tags = try(each.value.iam_role_tags, var.eks_managed_node_group_defaults.iam_role_tags, {})
iam_role_attach_cni_policy = try(each.value.iam_role_attach_cni_policy, var.eks_managed_node_group_defaults.iam_role_attach_cni_policy, true)
# To better understand why this `lookup()` logic is required, see:
# https://github.com/hashicorp/terraform/issues/31646#issuecomment-1217279031
iam_role_additional_policies = lookup(each.value, "iam_role_additional_policies", lookup(var.eks_managed_node_group_defaults, "iam_role_additional_policies", {}))
create_iam_role_policy = try(each.value.create_iam_role_policy, var.eks_managed_node_group_defaults.create_iam_role_policy, true)
iam_role_policy_statements = try(each.value.iam_role_policy_statements, var.eks_managed_node_group_defaults.iam_role_policy_statements, [])
# Autoscaling group schedule
create_schedule = try(each.value.create_schedule, var.eks_managed_node_group_defaults.create_schedule, true)
schedules = try(each.value.schedules, var.eks_managed_node_group_defaults.schedules, {})
create_iam_role = each.value.create_iam_role
iam_role_arn = each.value.iam_role_arn
iam_role_name = each.value.iam_role_name
iam_role_use_name_prefix = each.value.iam_role_use_name_prefix
iam_role_path = each.value.iam_role_path
iam_role_description = each.value.iam_role_description
iam_role_permissions_boundary = each.value.iam_role_permissions_boundary
iam_role_tags = each.value.iam_role_tags
iam_role_attach_cni_policy = each.value.iam_role_attach_cni_policy
iam_role_additional_policies = lookup(each.value, "iam_role_additional_policies", null)
create_iam_role_policy = each.value.create_iam_role_policy
iam_role_policy_statements = each.value.iam_role_policy_statements
# Security group
vpc_security_group_ids = compact(concat([local.node_security_group_id], try(each.value.vpc_security_group_ids, var.eks_managed_node_group_defaults.vpc_security_group_ids, [])))
cluster_primary_security_group_id = try(each.value.attach_cluster_primary_security_group, var.eks_managed_node_group_defaults.attach_cluster_primary_security_group, false) ? aws_eks_cluster.this[0].vpc_config[0].cluster_security_group_id : null
vpc_security_group_ids = compact(concat([local.node_security_group_id], each.value.vpc_security_group_ids))
cluster_primary_security_group_id = each.value.attach_cluster_primary_security_group ? aws_eks_cluster.this[0].vpc_config[0].cluster_security_group_id : null
create_security_group = each.value.create_security_group
security_group_name = each.value.security_group_name
security_group_use_name_prefix = each.value.security_group_use_name_prefix
security_group_description = each.value.security_group_description
security_group_ingress_rules = each.value.security_group_ingress_rules
security_group_egress_rules = each.value.security_group_egress_rules
security_group_tags = each.value.security_group_tags
tags = merge(var.tags, try(each.value.tags, var.eks_managed_node_group_defaults.tags, {}))
tags = merge(
var.tags,
each.value.tags,
)
}
################################################################################
@@ -419,150 +390,146 @@ module "eks_managed_node_group" {
module "self_managed_node_group" {
source = "./modules/self-managed-node-group"
for_each = { for k, v in var.self_managed_node_groups : k => v if var.create }
for_each = var.create && var.self_managed_node_groups != null ? var.self_managed_node_groups : {}
create = try(each.value.create, true)
create = each.value.create
cluster_name = time_sleep.this[0].triggers["cluster_name"]
region = var.region
# Pass through values to reduce GET requests from data sources
partition = local.partition
account_id = local.account_id
cluster_name = time_sleep.this[0].triggers["name"]
# Autoscaling Group
create_autoscaling_group = try(each.value.create_autoscaling_group, var.self_managed_node_group_defaults.create_autoscaling_group, true)
create_autoscaling_group = each.value.create_autoscaling_group
name = try(each.value.name, each.key)
use_name_prefix = try(each.value.use_name_prefix, var.self_managed_node_group_defaults.use_name_prefix, true)
name = coalesce(each.value.name, each.key)
use_name_prefix = each.value.use_name_prefix
availability_zones = try(each.value.availability_zones, var.self_managed_node_group_defaults.availability_zones, null)
subnet_ids = try(each.value.subnet_ids, var.self_managed_node_group_defaults.subnet_ids, var.subnet_ids)
availability_zones = each.value.availability_zones
subnet_ids = coalesce(each.value.subnet_ids, var.subnet_ids)
min_size = try(each.value.min_size, var.self_managed_node_group_defaults.min_size, 0)
max_size = try(each.value.max_size, var.self_managed_node_group_defaults.max_size, 3)
desired_size = try(each.value.desired_size, var.self_managed_node_group_defaults.desired_size, 1)
desired_size_type = try(each.value.desired_size_type, var.self_managed_node_group_defaults.desired_size_type, null)
capacity_rebalance = try(each.value.capacity_rebalance, var.self_managed_node_group_defaults.capacity_rebalance, null)
min_elb_capacity = try(each.value.min_elb_capacity, var.self_managed_node_group_defaults.min_elb_capacity, null)
wait_for_elb_capacity = try(each.value.wait_for_elb_capacity, var.self_managed_node_group_defaults.wait_for_elb_capacity, null)
wait_for_capacity_timeout = try(each.value.wait_for_capacity_timeout, var.self_managed_node_group_defaults.wait_for_capacity_timeout, null)
default_cooldown = try(each.value.default_cooldown, var.self_managed_node_group_defaults.default_cooldown, null)
default_instance_warmup = try(each.value.default_instance_warmup, var.self_managed_node_group_defaults.default_instance_warmup, null)
protect_from_scale_in = try(each.value.protect_from_scale_in, var.self_managed_node_group_defaults.protect_from_scale_in, null)
context = try(each.value.context, var.self_managed_node_group_defaults.context, null)
min_size = each.value.min_size
max_size = each.value.max_size
desired_size = each.value.desired_size
desired_size_type = each.value.desired_size_type
capacity_rebalance = each.value.capacity_rebalance
default_instance_warmup = each.value.default_instance_warmup
protect_from_scale_in = each.value.protect_from_scale_in
context = each.value.context
target_group_arns = try(each.value.target_group_arns, var.self_managed_node_group_defaults.target_group_arns, [])
create_placement_group = try(each.value.create_placement_group, var.self_managed_node_group_defaults.create_placement_group, false)
placement_group = try(each.value.placement_group, var.self_managed_node_group_defaults.placement_group, null)
placement_group_az = try(each.value.placement_group_az, var.self_managed_node_group_defaults.placement_group_az, null)
health_check_type = try(each.value.health_check_type, var.self_managed_node_group_defaults.health_check_type, null)
health_check_grace_period = try(each.value.health_check_grace_period, var.self_managed_node_group_defaults.health_check_grace_period, null)
create_placement_group = each.value.create_placement_group
placement_group = each.value.placement_group
health_check_type = each.value.health_check_type
health_check_grace_period = each.value.health_check_grace_period
ignore_failed_scaling_activities = try(each.value.ignore_failed_scaling_activities, var.self_managed_node_group_defaults.ignore_failed_scaling_activities, null)
ignore_failed_scaling_activities = each.value.ignore_failed_scaling_activities
force_delete = try(each.value.force_delete, var.self_managed_node_group_defaults.force_delete, null)
force_delete_warm_pool = try(each.value.force_delete_warm_pool, var.self_managed_node_group_defaults.force_delete_warm_pool, null)
termination_policies = try(each.value.termination_policies, var.self_managed_node_group_defaults.termination_policies, [])
suspended_processes = try(each.value.suspended_processes, var.self_managed_node_group_defaults.suspended_processes, [])
max_instance_lifetime = try(each.value.max_instance_lifetime, var.self_managed_node_group_defaults.max_instance_lifetime, null)
force_delete = each.value.force_delete
termination_policies = each.value.termination_policies
suspended_processes = each.value.suspended_processes
max_instance_lifetime = each.value.max_instance_lifetime
enabled_metrics = try(each.value.enabled_metrics, var.self_managed_node_group_defaults.enabled_metrics, [])
metrics_granularity = try(each.value.metrics_granularity, var.self_managed_node_group_defaults.metrics_granularity, null)
service_linked_role_arn = try(each.value.service_linked_role_arn, var.self_managed_node_group_defaults.service_linked_role_arn, null)
enabled_metrics = each.value.enabled_metrics
metrics_granularity = each.value.metrics_granularity
initial_lifecycle_hooks = try(each.value.initial_lifecycle_hooks, var.self_managed_node_group_defaults.initial_lifecycle_hooks, [])
instance_maintenance_policy = try(each.value.instance_maintenance_policy, var.self_managed_node_group_defaults.instance_maintenance_policy, {})
instance_refresh = try(each.value.instance_refresh, var.self_managed_node_group_defaults.instance_refresh, local.default_instance_refresh)
use_mixed_instances_policy = try(each.value.use_mixed_instances_policy, var.self_managed_node_group_defaults.use_mixed_instances_policy, false)
mixed_instances_policy = try(each.value.mixed_instances_policy, var.self_managed_node_group_defaults.mixed_instances_policy, null)
warm_pool = try(each.value.warm_pool, var.self_managed_node_group_defaults.warm_pool, {})
initial_lifecycle_hooks = each.value.initial_lifecycle_hooks
instance_maintenance_policy = each.value.instance_maintenance_policy
instance_refresh = each.value.instance_refresh
use_mixed_instances_policy = each.value.use_mixed_instances_policy
mixed_instances_policy = each.value.mixed_instances_policy
delete_timeout = try(each.value.delete_timeout, var.self_managed_node_group_defaults.delete_timeout, null)
autoscaling_group_tags = try(each.value.autoscaling_group_tags, var.self_managed_node_group_defaults.autoscaling_group_tags, {})
timeouts = each.value.timeouts
autoscaling_group_tags = each.value.autoscaling_group_tags
# User data
platform = try(each.value.platform, var.self_managed_node_group_defaults.platform, null)
# TODO - update this when `var.platform` is removed in v21.0
ami_type = try(each.value.ami_type, var.self_managed_node_group_defaults.ami_type, "AL2_x86_64")
cluster_endpoint = try(time_sleep.this[0].triggers["cluster_endpoint"], "")
cluster_auth_base64 = try(time_sleep.this[0].triggers["cluster_certificate_authority_data"], "")
cluster_service_cidr = try(time_sleep.this[0].triggers["cluster_service_cidr"], "")
additional_cluster_dns_ips = try(each.value.additional_cluster_dns_ips, var.self_managed_node_group_defaults.additional_cluster_dns_ips, [])
cluster_ip_family = var.cluster_ip_family
pre_bootstrap_user_data = try(each.value.pre_bootstrap_user_data, var.self_managed_node_group_defaults.pre_bootstrap_user_data, "")
post_bootstrap_user_data = try(each.value.post_bootstrap_user_data, var.self_managed_node_group_defaults.post_bootstrap_user_data, "")
bootstrap_extra_args = try(each.value.bootstrap_extra_args, var.self_managed_node_group_defaults.bootstrap_extra_args, "")
user_data_template_path = try(each.value.user_data_template_path, var.self_managed_node_group_defaults.user_data_template_path, "")
cloudinit_pre_nodeadm = try(each.value.cloudinit_pre_nodeadm, var.self_managed_node_group_defaults.cloudinit_pre_nodeadm, [])
cloudinit_post_nodeadm = try(each.value.cloudinit_post_nodeadm, var.self_managed_node_group_defaults.cloudinit_post_nodeadm, [])
ami_type = try(each.value.ami_type, null)
cluster_endpoint = try(time_sleep.this[0].triggers["endpoint"], "")
cluster_auth_base64 = try(time_sleep.this[0].triggers["certificate_authority_data"], "")
cluster_service_cidr = try(time_sleep.this[0].triggers["service_cidr"], "")
additional_cluster_dns_ips = try(each.value.additional_cluster_dns_ips, null)
cluster_ip_family = var.ip_family
pre_bootstrap_user_data = try(each.value.pre_bootstrap_user_data, null)
post_bootstrap_user_data = try(each.value.post_bootstrap_user_data, null)
bootstrap_extra_args = try(each.value.bootstrap_extra_args, null)
user_data_template_path = try(each.value.user_data_template_path, null)
cloudinit_pre_nodeadm = try(each.value.cloudinit_pre_nodeadm, null)
cloudinit_post_nodeadm = try(each.value.cloudinit_post_nodeadm, null)
# Launch Template
create_launch_template = try(each.value.create_launch_template, var.self_managed_node_group_defaults.create_launch_template, true)
launch_template_id = try(each.value.launch_template_id, var.self_managed_node_group_defaults.launch_template_id, "")
launch_template_name = try(each.value.launch_template_name, var.self_managed_node_group_defaults.launch_template_name, each.key)
launch_template_use_name_prefix = try(each.value.launch_template_use_name_prefix, var.self_managed_node_group_defaults.launch_template_use_name_prefix, true)
launch_template_version = try(each.value.launch_template_version, var.self_managed_node_group_defaults.launch_template_version, null)
launch_template_default_version = try(each.value.launch_template_default_version, var.self_managed_node_group_defaults.launch_template_default_version, null)
update_launch_template_default_version = try(each.value.update_launch_template_default_version, var.self_managed_node_group_defaults.update_launch_template_default_version, true)
launch_template_description = try(each.value.launch_template_description, var.self_managed_node_group_defaults.launch_template_description, "Custom launch template for ${try(each.value.name, each.key)} self managed node group")
launch_template_tags = try(each.value.launch_template_tags, var.self_managed_node_group_defaults.launch_template_tags, {})
tag_specifications = try(each.value.tag_specifications, var.self_managed_node_group_defaults.tag_specifications, ["instance", "volume", "network-interface"])
create_launch_template = try(each.value.create_launch_template, null)
launch_template_id = try(each.value.launch_template_id, null)
launch_template_name = coalesce(each.value.launch_template_name, each.key)
launch_template_use_name_prefix = try(each.value.launch_template_use_name_prefix, null)
launch_template_version = try(each.value.launch_template_version, null)
launch_template_default_version = try(each.value.launch_template_default_version, null)
update_launch_template_default_version = try(each.value.update_launch_template_default_version, null)
launch_template_description = coalesce(each.value.launch_template_description, "Custom launch template for ${coalesce(each.value.name, each.key)} self managed node group")
launch_template_tags = try(each.value.launch_template_tags, null)
tag_specifications = try(each.value.tag_specifications, null)
ebs_optimized = try(each.value.ebs_optimized, var.self_managed_node_group_defaults.ebs_optimized, null)
ami_id = try(each.value.ami_id, var.self_managed_node_group_defaults.ami_id, "")
cluster_version = try(each.value.cluster_version, var.self_managed_node_group_defaults.cluster_version, time_sleep.this[0].triggers["cluster_version"])
instance_type = try(each.value.instance_type, var.self_managed_node_group_defaults.instance_type, "m6i.large")
key_name = try(each.value.key_name, var.self_managed_node_group_defaults.key_name, null)
ebs_optimized = try(each.value.ebs_optimized, null)
ami_id = try(each.value.ami_id, null)
kubernetes_version = try(each.value.kubernetes_version, time_sleep.this[0].triggers["kubernetes_version"])
instance_type = try(each.value.instance_type, null)
key_name = try(each.value.key_name, null)
disable_api_termination = try(each.value.disable_api_termination, var.self_managed_node_group_defaults.disable_api_termination, null)
instance_initiated_shutdown_behavior = try(each.value.instance_initiated_shutdown_behavior, var.self_managed_node_group_defaults.instance_initiated_shutdown_behavior, null)
kernel_id = try(each.value.kernel_id, var.self_managed_node_group_defaults.kernel_id, null)
ram_disk_id = try(each.value.ram_disk_id, var.self_managed_node_group_defaults.ram_disk_id, null)
disable_api_termination = try(each.value.disable_api_termination, null)
instance_initiated_shutdown_behavior = try(each.value.instance_initiated_shutdown_behavior, null)
kernel_id = try(each.value.kernel_id, null)
ram_disk_id = try(each.value.ram_disk_id, null)
block_device_mappings = try(each.value.block_device_mappings, var.self_managed_node_group_defaults.block_device_mappings, {})
capacity_reservation_specification = try(each.value.capacity_reservation_specification, var.self_managed_node_group_defaults.capacity_reservation_specification, {})
cpu_options = try(each.value.cpu_options, var.self_managed_node_group_defaults.cpu_options, {})
credit_specification = try(each.value.credit_specification, var.self_managed_node_group_defaults.credit_specification, {})
elastic_gpu_specifications = try(each.value.elastic_gpu_specifications, var.self_managed_node_group_defaults.elastic_gpu_specifications, {})
elastic_inference_accelerator = try(each.value.elastic_inference_accelerator, var.self_managed_node_group_defaults.elastic_inference_accelerator, {})
enclave_options = try(each.value.enclave_options, var.self_managed_node_group_defaults.enclave_options, {})
hibernation_options = try(each.value.hibernation_options, var.self_managed_node_group_defaults.hibernation_options, {})
instance_requirements = try(each.value.instance_requirements, var.self_managed_node_group_defaults.instance_requirements, {})
instance_market_options = try(each.value.instance_market_options, var.self_managed_node_group_defaults.instance_market_options, {})
license_specifications = try(each.value.license_specifications, var.self_managed_node_group_defaults.license_specifications, {})
metadata_options = try(each.value.metadata_options, var.self_managed_node_group_defaults.metadata_options, local.metadata_options)
enable_monitoring = try(each.value.enable_monitoring, var.self_managed_node_group_defaults.enable_monitoring, true)
enable_efa_support = try(each.value.enable_efa_support, var.self_managed_node_group_defaults.enable_efa_support, false)
enable_efa_only = try(each.value.enable_efa_only, var.self_managed_node_group_defaults.enable_efa_only, false)
efa_indices = try(each.value.efa_indices, var.self_managed_node_group_defaults.efa_indices, [0])
network_interfaces = try(each.value.network_interfaces, var.self_managed_node_group_defaults.network_interfaces, [])
placement = try(each.value.placement, var.self_managed_node_group_defaults.placement, {})
maintenance_options = try(each.value.maintenance_options, var.self_managed_node_group_defaults.maintenance_options, {})
private_dns_name_options = try(each.value.private_dns_name_options, var.self_managed_node_group_defaults.private_dns_name_options, {})
block_device_mappings = try(each.value.block_device_mappings, null)
capacity_reservation_specification = try(each.value.capacity_reservation_specification, null)
cpu_options = try(each.value.cpu_options, null)
credit_specification = try(each.value.credit_specification, null)
enclave_options = try(each.value.enclave_options, null)
instance_requirements = try(each.value.instance_requirements, null)
instance_market_options = try(each.value.instance_market_options, null)
license_specifications = try(each.value.license_specifications, null)
metadata_options = try(each.value.metadata_options, null)
enable_monitoring = try(each.value.enable_monitoring, null)
enable_efa_support = try(each.value.enable_efa_support, null)
enable_efa_only = try(each.value.enable_efa_only, null)
efa_indices = try(each.value.efa_indices, null)
network_interfaces = try(each.value.network_interfaces, null)
placement = try(each.value.placement, null)
maintenance_options = try(each.value.maintenance_options, null)
private_dns_name_options = try(each.value.private_dns_name_options, null)
# IAM role
create_iam_instance_profile = try(each.value.create_iam_instance_profile, var.self_managed_node_group_defaults.create_iam_instance_profile, true)
iam_instance_profile_arn = try(each.value.iam_instance_profile_arn, var.self_managed_node_group_defaults.iam_instance_profile_arn, null)
iam_role_name = try(each.value.iam_role_name, var.self_managed_node_group_defaults.iam_role_name, null)
iam_role_use_name_prefix = try(each.value.iam_role_use_name_prefix, var.self_managed_node_group_defaults.iam_role_use_name_prefix, true)
iam_role_path = try(each.value.iam_role_path, var.self_managed_node_group_defaults.iam_role_path, null)
iam_role_description = try(each.value.iam_role_description, var.self_managed_node_group_defaults.iam_role_description, "Self managed node group IAM role")
iam_role_permissions_boundary = try(each.value.iam_role_permissions_boundary, var.self_managed_node_group_defaults.iam_role_permissions_boundary, null)
iam_role_tags = try(each.value.iam_role_tags, var.self_managed_node_group_defaults.iam_role_tags, {})
iam_role_attach_cni_policy = try(each.value.iam_role_attach_cni_policy, var.self_managed_node_group_defaults.iam_role_attach_cni_policy, true)
# To better understand why this `lookup()` logic is required, see:
# https://github.com/hashicorp/terraform/issues/31646#issuecomment-1217279031
iam_role_additional_policies = lookup(each.value, "iam_role_additional_policies", lookup(var.self_managed_node_group_defaults, "iam_role_additional_policies", {}))
create_iam_role_policy = try(each.value.create_iam_role_policy, var.self_managed_node_group_defaults.create_iam_role_policy, true)
iam_role_policy_statements = try(each.value.iam_role_policy_statements, var.self_managed_node_group_defaults.iam_role_policy_statements, [])
create_iam_instance_profile = try(each.value.create_iam_instance_profile, null)
iam_instance_profile_arn = try(each.value.iam_instance_profile_arn, null)
iam_role_name = try(each.value.iam_role_name, null)
iam_role_use_name_prefix = try(each.value.iam_role_use_name_prefix, true)
iam_role_path = try(each.value.iam_role_path, null)
iam_role_description = try(each.value.iam_role_description, null)
iam_role_permissions_boundary = try(each.value.iam_role_permissions_boundary, null)
iam_role_tags = try(each.value.iam_role_tags, null)
iam_role_attach_cni_policy = try(each.value.iam_role_attach_cni_policy, null)
iam_role_additional_policies = lookup(each.value, "iam_role_additional_policies", null)
create_iam_role_policy = try(each.value.create_iam_role_policy, null)
iam_role_policy_statements = try(each.value.iam_role_policy_statements, null)
# Access entry
create_access_entry = try(each.value.create_access_entry, var.self_managed_node_group_defaults.create_access_entry, true)
iam_role_arn = try(each.value.iam_role_arn, var.self_managed_node_group_defaults.iam_role_arn, null)
# Autoscaling group schedule
create_schedule = try(each.value.create_schedule, var.self_managed_node_group_defaults.create_schedule, true)
schedules = try(each.value.schedules, var.self_managed_node_group_defaults.schedules, {})
create_access_entry = try(each.value.create_access_entry, null)
iam_role_arn = try(each.value.iam_role_arn, null)
# Security group
vpc_security_group_ids = compact(concat([local.node_security_group_id], try(each.value.vpc_security_group_ids, var.self_managed_node_group_defaults.vpc_security_group_ids, [])))
cluster_primary_security_group_id = try(each.value.attach_cluster_primary_security_group, var.self_managed_node_group_defaults.attach_cluster_primary_security_group, false) ? aws_eks_cluster.this[0].vpc_config[0].cluster_security_group_id : null
vpc_security_group_ids = compact(concat([local.node_security_group_id], try(each.value.vpc_security_group_ids, [])))
cluster_primary_security_group_id = try(each.value.attach_cluster_primary_security_group, false) ? aws_eks_cluster.this[0].vpc_config[0].cluster_security_group_id : null
create_security_group = try(each.value.create_security_group, null)
security_group_name = try(each.value.security_group_name, null)
security_group_use_name_prefix = try(each.value.security_group_use_name_prefix, null)
security_group_description = try(each.value.security_group_description, null)
security_group_ingress_rules = try(each.value.security_group_ingress_rules, null)
security_group_egress_rules = try(each.value.security_group_egress_rules, null)
security_group_tags = try(each.value.security_group_tags, null)
tags = merge(var.tags, try(each.value.tags, var.self_managed_node_group_defaults.tags, {}))
tags = merge(
var.tags,
each.value.tags,
)
}