Part 2 — Build as code · wrap-up
Cheat sheet & self-check
Every command from this section on one page.
Network layer
terraform -chdir=live/prod/10-network plan | Review network changes |
terraform -chdir=live/prod/10-network state list | grep subnet | Subnets in state |
terraform -chdir=live/prod/10-network output private_subnets | Private subnet IDs |
aws ec2 describe-subnets --filters Name=tag:karpenter.sh/discovery,Values=prod --query 'Subnets[].SubnetId' | Subnets Karpenter will use |
Cluster layer
terraform -chdir=live/prod/20-cluster plan | grep -E 'must be replaced|forces replacement' | Catch replacements before they happen |
terraform -chdir=live/prod/20-cluster state show aws_eks_cluster.this | Everything Terraform knows about the cluster |
aws eks update-kubeconfig --name prod --alias prod | kubeconfig after apply |
aws eks describe-addon-versions --addon-name coredns --kubernetes-version 1.33 --query 'addons[].addonVersions[].addonVersion' | Valid add-on versions to pin |
Review identity in code and in AWS
terraform -chdir=live/prod/30-platform state list | grep -E 'access_entry|pod_identity|iam_role' | Identity resources Terraform owns |
aws eks list-access-entries --cluster-name prod | Compare with what exists (drift) |
aws eks list-pod-identity-associations --cluster-name prod --query 'associations[].[namespace,serviceAccount]' --output table | Which ServiceAccounts have roles |
aws iam simulate-principal-policy --policy-source-arn <role-arn> --action-names s3:GetObject --resource-arns arn:aws:s3:::bucket/shop/x | Test a role's permissions without calling the service |
Platform layer
terraform -chdir=live/prod/30-platform apply | IAM, queues, Karpenter and Argo CD bootstrap |
helm list -A | Helm releases in the cluster (who installed what) |
kubectl get applications -n argocd | Everything Argo CD owns |
kubectl get secret -n argocd -l argocd.argoproj.io/secret-type=cluster -o yaml | Cluster secret with Terraform-provided annotations |
kubectl get nodepools,ec2nodeclasses | Karpenter configuration (owned by GitOps) |