Manage EKS with Terraform›Part 1 · Cheat sheet & self-check
Learning Hub / Cloud — OpenStack, AWS & EKS / Manage EKS with Terraform

Part 1 — Foundations · wrap-up

Cheat sheet & self-check

Every command from this section on one page.

01 · Repo layout & run order

Working in a layer

terraform -chdir=live/prod/20-cluster initInitialise one layer of one environment
terraform -chdir=live/prod/20-cluster plan -out=tfplanPlan and save it
terraform -chdir=live/prod/20-cluster apply tfplanApply exactly what was reviewed
terraform providers lock -platform=linux_amd64 -platform=darwin_arm64Lock provider hashes for all platforms your team uses
terraform fmt -recursive && terraform validateFormatting and static checks

Across layers

for l in 10-network 20-cluster 30-platform; do terraform -chdir=live/prod/$l apply; doneCreate in order
for l in 30-platform 20-cluster 10-network; do terraform -chdir=live/prod/$l destroy; doneDestroy in reverse order
aws ssm get-parameter --name /platform/prod/vpc_idRead an output another layer published

02 · Remote state: S3, locking, env-per-tfvars

State

terraform init -backend-config=backend-prod.hclInitialise against an environment's backend
terraform state listResources tracked in state
terraform state show module.eks.aws_eks_cluster.this[0]One resource's recorded attributes
terraform force-unlock <lock-id>Remove a stale lock (only when sure nobody is running!)

Plans & drift

terraform plan -var-file=prod.tfvars -out=prod.planPlan and save it
terraform apply prod.planApply exactly what was planned
terraform plan -detailed-exitcodeExit 0 = no changes, 2 = changes (drift), 1 = error

03 · The multi-provider chicken-and-egg

Patterns

exec { command = "aws" args = ["eks", "get-token", …] }Fresh tokens during long applies
data "terraform_remote_state" "cluster" { … }Read the cluster layer's outputs from another stack
terraform apply -target=module.eksEmergency only: bootstrap one part first

Useful commands

aws eks get-token --cluster-name prod | jq -r .status.expirationTimestampWhen does this token expire?
terraform providersWhich providers each module uses