Skip to main content

Amazon EKS cluster

A minimal AWS Python EKS example cluster

This example lives in the pulumi/examples repository. Check out just this directory to use it:

Get started with this example
git clone --filter=blob:none --sparse https://github.com/pulumi/examples pulumi-examples
git -C pulumi-examples sparse-checkout set aws-py-eks
cd pulumi-examples/aws-py-eks

This example deploys an EKS Kubernetes cluster inside an AWS VPC with proper NodeGroup and networking configured.

Prerequisites#

  1. Install Pulumi
  2. Configure AWS credentials
  3. Install Python
  4. Optional for K8s auth: Install iam-authenticator

Deploying the example#

  1. Create a new stack:

    Terminal window
    pulumi stack init python-eks-testing
  2. Set the AWS region to deploy into:

    Terminal window
    pulumi config set aws:region us-east-2
  3. Install dependencies:

    Terminal window
    python3 -m venv venv
    source venv/bin/activate
    pip install -r requirements.txt
  4. Run pulumi up to preview and deploy changes:

    Terminal window
    pulumi up
    Previewing stack 'python-eks-testing'
    Previewing changes:
    ...
    Do you want to perform this update? yes
    Updating (python-eks-testing):
    Type Name Status
    + pulumi:pulumi:Stack aws-py-eks-python-eks-testing created
    + ├─ aws:iam:Role ec2-nodegroup-iam-role created
    + ├─ aws:iam:Role eks-iam-role created
    + ├─ aws:ec2:Vpc eks-vpc created
    + ├─ aws:iam:RolePolicyAttachment eks-workernode-policy-attachment created
    + ├─ aws:iam:RolePolicyAttachment eks-cni-policy-attachment created
    + ├─ aws:iam:RolePolicyAttachment ec2-container-ro-policy-attachment created
    + ├─ aws:iam:RolePolicyAttachment eks-service-policy-attachment created
    + ├─ aws:iam:RolePolicyAttachment eks-cluster-policy-attachment created
    + ├─ aws:ec2:InternetGateway vpc-ig created
    + ├─ aws:ec2:Subnet vpc-sn-1 created
    + ├─ aws:ec2:Subnet vpc-sn-2 created
    + ├─ aws:ec2:SecurityGroup eks-cluster-sg created
    + ├─ aws:ec2:RouteTable vpc-route-table created
    + ├─ aws:eks:Cluster eks-cluster created
    + ├─ aws:ec2:RouteTableAssociation vpc-1-route-table-assoc created
    + ├─ aws:ec2:RouteTableAssociation vpc-2-route-table-assoc created
    + └─ aws:eks:NodeGroup eks-node-group created
    Outputs:
    cluster-name: "eks-cluster-96b87e8"
    Resources:
    + 18 created
    Duration: 14m15s
  5. View the cluster name via pulumi stack output:

    Terminal window
    pulumi stack output
    Current stack outputs (1):
    OUTPUT VALUE
    cluster-name eks-cluster-96b87e8
  6. Verify that the EKS cluster exists, by either using the AWS Console or running aws eks list-clusters.

  7. Update your kubeconfig, authenticate to your Kubernetes cluster, and verify you have API access and nodes running:

    Terminal window
    aws eks --region us-east-2 update-kubeconfig --name $(pulumi stack output cluster-name)
    Added new context arn:aws:eks:us-east-2:account:cluster/eks-cluster-96b87e8
    Terminal window
    kubectl get nodes
    NAME STATUS ROLES AGE VERSION
    ip-10-100-0-182.us-east-2.compute.internal Ready <none> 10m v1.14.7-eks-1861c5
    ip-10-100-1-174.us-east-2.compute.internal Ready <none> 10m v1.14.7-eks-1861c5

Cleaning up#

To clean up resources, run pulumi destroy and answer the confirmation question at the prompt. Then run pulumi stack rm to remove the stack.

Related

The infrastructure as code platform for any cloud.