Amazon EKS in Production with Terraform›Playbooks, challenges & practice · Cheat sheet & self-check
Learning Hub / Cloud — OpenStack, AWS & EKS / Amazon EKS in Production with Terraform

Playbooks, challenges & practice · wrap-up

Cheat sheet & self-check

18 questions across 6 lessons. Each answer links back to the lesson it came from.

Pick an answer to see if you got it, and why.

  1. Q1. Why apply the stack layer by layer with verification gates?

    Show answer

    B. A broken VPC discovered after the platform layer is installed is much harder to untangle.

    From lesson 13 · Playbook: creating the cluster
  2. Q2. What must you check in the plan before applying the cluster layer for the first time?

    Show answer

    B. Plan review is the cheapest place to catch mistakes.

    From lesson 13 · Playbook: creating the cluster
  3. Q3. The platform layer fails halfway (a Helm release times out). What's the safe response?

    Show answer

    B. Layered states make a failed layer re-runnable without touching the others.

    From lesson 13 · Playbook: creating the cluster
  4. Q4. What's the correct order for a Kubernetes minor upgrade on this stack?

    Show answer

    B. The control plane may be at most a limited number of versions ahead of nodes; never behind.

    From lesson 14 · Playbook: day-2 operations
  5. Q5. Why delete LoadBalancer Services/Ingresses and Karpenter NodePools before `terraform destroy`?

    Show answer

    B. Let the creators clean up their own resources first.

    From lesson 14 · Playbook: day-2 operations
  6. Q6. How should a team get access to the cluster?

    Show answer

    B. Reviewed, auditable, least-privilege access through the EKS API.

    From lesson 14 · Playbook: day-2 operations
  7. Q7. How does kubectl authenticate to EKS after `aws eks update-kubeconfig`?

    Show answer

    B. No long-lived secrets in the kubeconfig; access follows your IAM session.

    From lesson 15 · The flow: laptop → cluster → kubeconfig → app
  8. Q8. In the CI/CD way of working, who writes to production?

    Show answer

    B. Changes become reviewed, logged and repeatable.

    From lesson 15 · The flow: laptop → cluster → kubeconfig → app
  9. Q9. Why push images by digest and deploy the digest?

    Show answer

    B. See CI/CD & Software Supply Chain, lesson 05.

    From lesson 15 · The flow: laptop → cluster → kubeconfig → app
  10. Q10. A plan shows the EKS cluster 'must be replaced'. What do you do?

    Show answer

    B. Replacing a cluster deletes it. Plans are where you catch this.

    From lesson 16 · Challenges on this stack
  11. Q11. A pod is Pending with a volume node affinity conflict after rescheduling. Why?

    Show answer

    B. Use WaitForFirstConsumer, keep capacity in every AZ used by volumes, or use EFS for shared/multi-AZ needs.

    From lesson 16 · Challenges on this stack
  12. Q12. Karpenter logs say no instance types satisfy the requirements. What's a likely cause?

    Show answer

    B. Read the NodeClaim events and Karpenter logs; widen requirements or fix selector tags.

    From lesson 16 · Challenges on this stack
  13. Q13. When is `terraform force-unlock` safe?

    Show answer

    B. Check the lock info (who, when, operation) and your pipelines first.

    From lesson 17 · Recovery playbook
  14. Q14. The state file was overwritten by a bad apply. What's the recovery path with a versioned S3 bucket?

    Show answer

    B. Versioning is the reason you enabled it in lesson 02. Verify with a plan afterwards.

    From lesson 17 · Recovery playbook
  15. Q15. `terraform destroy` of the network layer hangs deleting a subnet. What's the usual cause?

    Show answer

    B. Always clean up controller-created resources before destroying lower layers.

    From lesson 17 · Recovery playbook
  16. Q16. What can `terraform test` with a mock AWS provider verify?

    Show answer

    B. It's unit testing for Terraform code, fast and free, not an integration test.

    From lesson 18 · Simulator: practise for $0
  17. Q17. Which part of this course can't be simulated faithfully offline?

    Show answer

    B. Use a short, budgeted real session for these, and destroy afterwards.

    From lesson 18 · Simulator: practise for $0
  18. Q18. Why rehearse the platform layer on kind?

    Show answer

    B. Swap ALB for an ingress controller, EBS CSI for local-path, Karpenter for fixed nodes.

    From lesson 18 · Simulator: practise for $0