mirror of
https://github.com/terraform-aws-modules/terraform-aws-eks.git
synced 2025-09-09 19:32:58 +08:00
Deployed 416515a with MkDocs version: 1.6.1
This commit is contained in:
+34
-12
@@ -337,9 +337,9 @@
|
||||
</li>
|
||||
|
||||
<li class="md-nav__item">
|
||||
<a href="#i-received-an-error-expect-exactly-one-securitygroup-tagged-with-kubernetesioclustername" class="md-nav__link">
|
||||
<a href="#i-received-an-error-expect-exactly-one-securitygroup-tagged-with-kubernetesioclustercluster_name" class="md-nav__link">
|
||||
<span class="md-ellipsis">
|
||||
I received an error: expect exactly one securityGroup tagged with kubernetes.io/cluster/<NAME> ...
|
||||
I received an error: expect exactly one securityGroup tagged with kubernetes.io/cluster/<CLUSTER_NAME> ...
|
||||
</span>
|
||||
</a>
|
||||
|
||||
@@ -420,19 +420,40 @@
|
||||
</ul>
|
||||
<h3 id="setting-disk_size-or-remote_access-does-not-make-any-changes">Setting <code>disk_size</code> or <code>remote_access</code> does not make any changes<a class="headerlink" href="#setting-disk_size-or-remote_access-does-not-make-any-changes" title="Permanent link">¶</a></h3>
|
||||
<p><code>disk_size</code>, and <code>remote_access</code> can only be set when using the EKS managed node group default launch template. This module defaults to providing a custom launch template to allow for custom security groups, tag propagation, etc. If you wish to forgo the custom launch template route, you can set <code>use_custom_launch_template = false</code> and then you can set <code>disk_size</code> and <code>remote_access</code>.</p>
|
||||
<h3 id="i-received-an-error-expect-exactly-one-securitygroup-tagged-with-kubernetesioclustername">I received an error: <code>expect exactly one securityGroup tagged with kubernetes.io/cluster/<NAME> ...</code><a class="headerlink" href="#i-received-an-error-expect-exactly-one-securitygroup-tagged-with-kubernetesioclustername" title="Permanent link">¶</a></h3>
|
||||
<h3 id="i-received-an-error-expect-exactly-one-securitygroup-tagged-with-kubernetesioclustercluster_name">I received an error: <code>expect exactly one securityGroup tagged with kubernetes.io/cluster/<CLUSTER_NAME> ...</code><a class="headerlink" href="#i-received-an-error-expect-exactly-one-securitygroup-tagged-with-kubernetesioclustercluster_name" title="Permanent link">¶</a></h3>
|
||||
<p>⚠️ <code><CLUSTER_NAME></code> would be the name of your cluster</p>
|
||||
<p>By default, EKS creates a cluster primary security group that is created outside of the module and the EKS service adds the tag <code>{ "kubernetes.io/cluster/<CLUSTER_NAME>" = "owned" }</code>. This on its own does not cause any conflicts for addons such as the AWS Load Balancer Controller until users decide to attach both the cluster primary security group and the shared node security group created by the module (by setting <code>attach_cluster_primary_security_group = true</code>). The issue is not with having multiple security groups in your account with this tag key:value combination, but having multiple security groups with this tag key:value combination attached to nodes in the same cluster. There are a few ways to resolve this depending on your use case/intentions:</p>
|
||||
<p>⚠️ <code><CLUSTER_NAME></code> below needs to be replaced with the name of your cluster</p>
|
||||
<ol>
|
||||
<li>If you want to use the cluster primary security group, you can disable the creation of the shared node security group with:</li>
|
||||
</ol>
|
||||
<div class="language-hcl highlight"><pre><span></span><code><span id="__span-0-1"><a id="__codelineno-0-1" name="__codelineno-0-1" href="#__codelineno-0-1"></a><span class="w"> </span><span class="na">create_node_security_group</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="no">false</span><span class="c1"> # default is true</span>
|
||||
</span><span id="__span-0-2"><a id="__codelineno-0-2" name="__codelineno-0-2" href="#__codelineno-0-2"></a><span class="w"> </span><span class="na">attach_cluster_primary_security_group</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="no">true</span><span class="c1"> # default is false</span>
|
||||
<div class="language-hcl highlight"><pre><span></span><code><span id="__span-0-1"><a id="__codelineno-0-1" name="__codelineno-0-1" href="#__codelineno-0-1"></a><span class="w"> </span><span class="na">create_node_security_group</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="no">false</span><span class="c1"> # default is true</span>
|
||||
</span><span id="__span-0-2"><a id="__codelineno-0-2" name="__codelineno-0-2" href="#__codelineno-0-2"></a>
|
||||
</span><span id="__span-0-3"><a id="__codelineno-0-3" name="__codelineno-0-3" href="#__codelineno-0-3"></a><span class="w"> </span><span class="nb">eks_managed_node_group</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">{</span>
|
||||
</span><span id="__span-0-4"><a id="__codelineno-0-4" name="__codelineno-0-4" href="#__codelineno-0-4"></a><span class="w"> </span><span class="nb">example</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">{</span>
|
||||
</span><span id="__span-0-5"><a id="__codelineno-0-5" name="__codelineno-0-5" href="#__codelineno-0-5"></a><span class="w"> </span><span class="na">attach_cluster_primary_security_group</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="no">true</span><span class="c1"> # default is false</span>
|
||||
</span><span id="__span-0-6"><a id="__codelineno-0-6" name="__codelineno-0-6" href="#__codelineno-0-6"></a><span class="w"> </span><span class="p">}</span>
|
||||
</span><span id="__span-0-7"><a id="__codelineno-0-7" name="__codelineno-0-7" href="#__codelineno-0-7"></a><span class="w"> </span><span class="p">}</span>
|
||||
</span><span id="__span-0-8"><a id="__codelineno-0-8" name="__codelineno-0-8" href="#__codelineno-0-8"></a><span class="c1"> # Or for self-managed</span>
|
||||
</span><span id="__span-0-9"><a id="__codelineno-0-9" name="__codelineno-0-9" href="#__codelineno-0-9"></a><span class="w"> </span><span class="nb">self_managed_node_group</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">{</span>
|
||||
</span><span id="__span-0-10"><a id="__codelineno-0-10" name="__codelineno-0-10" href="#__codelineno-0-10"></a><span class="w"> </span><span class="nb">example</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">{</span>
|
||||
</span><span id="__span-0-11"><a id="__codelineno-0-11" name="__codelineno-0-11" href="#__codelineno-0-11"></a><span class="w"> </span><span class="na">attach_cluster_primary_security_group</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="no">true</span><span class="c1"> # default is false</span>
|
||||
</span><span id="__span-0-12"><a id="__codelineno-0-12" name="__codelineno-0-12" href="#__codelineno-0-12"></a><span class="w"> </span><span class="p">}</span>
|
||||
</span><span id="__span-0-13"><a id="__codelineno-0-13" name="__codelineno-0-13" href="#__codelineno-0-13"></a><span class="w"> </span><span class="p">}</span>
|
||||
</span></code></pre></div>
|
||||
<ol>
|
||||
<li>By not attaching the cluster primary security group. The cluster primary security group has quite broad access and the module has instead provided a security group with the minimum amount of access to launch an empty EKS cluster successfully and users are encouraged to open up access when necessary to support their workload.</li>
|
||||
</ol>
|
||||
<div class="language-hcl highlight"><pre><span></span><code><span id="__span-1-1"><a id="__codelineno-1-1" name="__codelineno-1-1" href="#__codelineno-1-1"></a><span class="w"> </span><span class="na">attach_cluster_primary_security_group</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="no">false</span><span class="c1"> # this is the default for the module</span>
|
||||
<div class="language-hcl highlight"><pre><span></span><code><span id="__span-1-1"><a id="__codelineno-1-1" name="__codelineno-1-1" href="#__codelineno-1-1"></a><span class="w"> </span><span class="nb">eks_managed_node_group</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">{</span>
|
||||
</span><span id="__span-1-2"><a id="__codelineno-1-2" name="__codelineno-1-2" href="#__codelineno-1-2"></a><span class="w"> </span><span class="nb">example</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">{</span>
|
||||
</span><span id="__span-1-3"><a id="__codelineno-1-3" name="__codelineno-1-3" href="#__codelineno-1-3"></a><span class="w"> </span><span class="na">attach_cluster_primary_security_group</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="no">true</span><span class="c1"> # default is false</span>
|
||||
</span><span id="__span-1-4"><a id="__codelineno-1-4" name="__codelineno-1-4" href="#__codelineno-1-4"></a><span class="w"> </span><span class="p">}</span>
|
||||
</span><span id="__span-1-5"><a id="__codelineno-1-5" name="__codelineno-1-5" href="#__codelineno-1-5"></a><span class="w"> </span><span class="p">}</span>
|
||||
</span><span id="__span-1-6"><a id="__codelineno-1-6" name="__codelineno-1-6" href="#__codelineno-1-6"></a><span class="c1"> # Or for self-managed</span>
|
||||
</span><span id="__span-1-7"><a id="__codelineno-1-7" name="__codelineno-1-7" href="#__codelineno-1-7"></a><span class="w"> </span><span class="nb">self_managed_node_group</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">{</span>
|
||||
</span><span id="__span-1-8"><a id="__codelineno-1-8" name="__codelineno-1-8" href="#__codelineno-1-8"></a><span class="w"> </span><span class="nb">example</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">{</span>
|
||||
</span><span id="__span-1-9"><a id="__codelineno-1-9" name="__codelineno-1-9" href="#__codelineno-1-9"></a><span class="w"> </span><span class="na">attach_cluster_primary_security_group</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="no">true</span><span class="c1"> # default is false</span>
|
||||
</span><span id="__span-1-10"><a id="__codelineno-1-10" name="__codelineno-1-10" href="#__codelineno-1-10"></a><span class="w"> </span><span class="p">}</span>
|
||||
</span><span id="__span-1-11"><a id="__codelineno-1-11" name="__codelineno-1-11" href="#__codelineno-1-11"></a><span class="w"> </span><span class="p">}</span>
|
||||
</span></code></pre></div>
|
||||
<p>In theory, if you are attaching the cluster primary security group, you shouldn't need to use the shared node security group created by the module. However, this is left up to users to decide for their requirements and use case.</p>
|
||||
<p>If you choose to use <a href="https://docs.aws.amazon.com/eks/latest/userguide/cni-custom-network.html">Custom Networking</a>, make sure to only attach the security groups matching your choice above in your ENIConfig resources. This will ensure you avoid redundant tags.</p>
|
||||
@@ -462,6 +483,7 @@
|
||||
</ol>
|
||||
<h3 id="why-are-there-no-changes-when-a-node-groups-desired_size-is-modified">Why are there no changes when a node group's <code>desired_size</code> is modified?<a class="headerlink" href="#why-are-there-no-changes-when-a-node-groups-desired_size-is-modified" title="Permanent link">¶</a></h3>
|
||||
<p>The module is configured to ignore this value. Unfortunately, Terraform does not support variables within the <code>lifecycle</code> block. The setting is ignored to allow autoscaling via controllers such as cluster autoscaler or Karpenter to work properly and without interference by Terraform. Changing the desired count must be handled outside of Terraform once the node group is created.</p>
|
||||
<p>:info: See <a href="https://github.com/bryantbiggs/eks-desired-size-hack">this</a> for a workaround to this limitation.</p>
|
||||
<h3 id="how-do-i-access-compute-resource-attributes">How do I access compute resource attributes?<a class="headerlink" href="#how-do-i-access-compute-resource-attributes" title="Permanent link">¶</a></h3>
|
||||
<p>Examples of accessing the attributes of the compute resource(s) created by the root module are shown below. Note - the assumption is that your cluster module definition is named <code>eks</code> as in <code>module "eks" { ... }</code>:</p>
|
||||
<ul>
|
||||
@@ -484,6 +506,11 @@
|
||||
<div class="language-sh highlight"><pre><span></span><code><span id="__span-5-1"><a id="__codelineno-5-1" name="__codelineno-5-1" href="#__codelineno-5-1"></a>aws<span class="w"> </span>eks<span class="w"> </span>describe-addon-versions<span class="w"> </span>--query<span class="w"> </span><span class="s1">'addons[*].addonName'</span>
|
||||
</span></code></pre></div>
|
||||
<h3 id="what-configuration-values-are-available-for-an-add-on">What configuration values are available for an add-on?<a class="headerlink" href="#what-configuration-values-are-available-for-an-add-on" title="Permanent link">¶</a></h3>
|
||||
<blockquote>
|
||||
<p>[!NOTE]
|
||||
The available configuration values will vary between add-on versions,
|
||||
typically more configuration values will be added in later versions as functionality is enabled by EKS.</p>
|
||||
</blockquote>
|
||||
<p>You can retrieve the configuration value schema for a given addon using the following command:</p>
|
||||
<div class="language-sh highlight"><pre><span></span><code><span id="__span-6-1"><a id="__codelineno-6-1" name="__codelineno-6-1" href="#__codelineno-6-1"></a>aws<span class="w"> </span>eks<span class="w"> </span>describe-addon-configuration<span class="w"> </span>--addon-name<span class="w"> </span><value><span class="w"> </span>--addon-version<span class="w"> </span><value><span class="w"> </span>--query<span class="w"> </span><span class="s1">'configurationSchema'</span><span class="w"> </span>--output<span class="w"> </span>text<span class="w"> </span><span class="p">|</span><span class="w"> </span>jq
|
||||
</span></code></pre></div>
|
||||
@@ -672,11 +699,6 @@
|
||||
</span><span id="__span-8-179"><a id="__codelineno-8-179" name="__codelineno-8-179" href="#__codelineno-8-179"></a><span class="w"> </span><span class="p">}</span>
|
||||
</span><span id="__span-8-180"><a id="__codelineno-8-180" name="__codelineno-8-180" href="#__codelineno-8-180"></a><span class="p">}</span>
|
||||
</span></code></pre></div>
|
||||
<blockquote>
|
||||
<p>[!NOTE]
|
||||
The available configuration values will vary between add-on versions,
|
||||
typically more configuration values will be added in later versions as functionality is enabled by EKS.</p>
|
||||
</blockquote>
|
||||
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user