Manage EKS with Terraform›Part 2 · Cheat sheet & self-check
Learning Hub / Cloud — OpenStack, AWS & EKS / Manage EKS with Terraform

Part 2 — Build as code · wrap-up

Cheat sheet & self-check

Every command from this section on one page.

04 · The VPC as code

Network layer

terraform -chdir=live/prod/10-network planReview network changes
terraform -chdir=live/prod/10-network state list | grep subnetSubnets in state
terraform -chdir=live/prod/10-network output private_subnetsPrivate subnet IDs
aws ec2 describe-subnets --filters Name=tag:karpenter.sh/discovery,Values=prod --query 'Subnets[].SubnetId'Subnets Karpenter will use

05 · The EKS cluster as code

Cluster layer

terraform -chdir=live/prod/20-cluster plan | grep -E 'must be replaced|forces replacement'Catch replacements before they happen
terraform -chdir=live/prod/20-cluster state show aws_eks_cluster.thisEverything Terraform knows about the cluster
aws eks update-kubeconfig --name prod --alias prodkubeconfig after apply
aws eks describe-addon-versions --addon-name coredns --kubernetes-version 1.33 --query 'addons[].addonVersions[].addonVersion'Valid add-on versions to pin

06 · IAM as code: access entries, Pod Identity & IRSA

Review identity in code and in AWS

terraform -chdir=live/prod/30-platform state list | grep -E 'access_entry|pod_identity|iam_role'Identity resources Terraform owns
aws eks list-access-entries --cluster-name prodCompare with what exists (drift)
aws eks list-pod-identity-associations --cluster-name prod --query 'associations[].[namespace,serviceAccount]' --output tableWhich ServiceAccounts have roles
aws iam simulate-principal-policy --policy-source-arn <role-arn> --action-names s3:GetObject --resource-arns arn:aws:s3:::bucket/shop/xTest a role's permissions without calling the service

07 · Add-ons, Karpenter & the GitOps hand-off

Platform layer

terraform -chdir=live/prod/30-platform applyIAM, queues, Karpenter and Argo CD bootstrap
helm list -AHelm releases in the cluster (who installed what)
kubectl get applications -n argocdEverything Argo CD owns
kubectl get secret -n argocd -l argocd.argoproj.io/secret-type=cluster -o yamlCluster secret with Terraform-provided annotations
kubectl get nodepools,ec2nodeclassesKarpenter configuration (owned by GitOps)