Part 2 — Build as code · wrap-up
Cheat sheet & self-check
12 questions across 4 lessons. Each answer links back to the lesson it came from.
Pick an answer to see if you got it, and why.
Q1. In the VPC module, what does one_nat_gateway_per_az = true (with single_nat_gateway = false) give you?
Show answer
B. Per-AZ NAT removes a cross-AZ single point of failure and cross-AZ data charges. Use single_nat_gateway for cheap dev environments.
From lesson 04 · The VPC as codeQ2. Why tag subnets with kubernetes.io/role/elb and kubernetes.io/role/internal-elb in Terraform?
Show answer
B. Subnet discovery by tag keeps load-balancer placement correct without hard-coding subnet IDs in every Ingress.
From lesson 04 · The VPC as codeQ3. What's the risk of changing the VPC CIDR or subnet CIDRs in Terraform later?
Show answer
B. CIDR changes force replacement. Plan address space generously once, and add a secondary CIDR rather than resizing.
From lesson 04 · The VPC as codeQ4. Why set bootstrap_cluster_creator_admin_permissions = false?
Show answer
B. The creator (often a CI role) would otherwise get hidden admin rights. Declaring admins as access entries keeps access reviewable in code.
From lesson 05 · The EKS cluster as codeQ5. Why ignore changes to desired_size on a managed node group?
Show answer
B. Terraform owns min and max; the autoscaler owns the current size. ignore_changes stops the two from fighting.
From lesson 05 · The EKS cluster as codeQ6. Why pin add-on versions instead of always using the latest?
Show answer
B. A data source with most_recent = true changes the plan whenever AWS publishes a version. Pin, then bump in a pull request.
From lesson 05 · The EKS cluster as codeQ7. Why build IAM policies with the aws_iam_policy_document data source instead of raw JSON strings?
Show answer
B. Policy documents in HCL are easier to review, reuse and combine; the data source renders normalised JSON.
From lesson 06 · IAM as code: access entries, Pod Identity & IRSAQ8. A module lets teams request pod roles. How do you stop a team role from granting itself admin?
Show answer
B. A boundary caps effective permissions regardless of attached policies; the SCP makes the boundary unavoidable.
From lesson 06 · IAM as code: access entries, Pod Identity & IRSAQ9. For IRSA in Terraform, which resource registers the cluster's issuer with IAM?
Show answer
B. IRSA needs the cluster's OIDC issuer as an IAM identity provider; role trust policies then reference it with sub and aud conditions.
From lesson 06 · IAM as code: access entries, Pod Identity & IRSAQ10. Which is the usual boundary between Terraform and GitOps on an EKS platform?
Show answer
B. Terraform is good at AWS APIs and ordering; Argo CD is good at continuously reconciling Kubernetes objects. Each does what it's best at.
From lesson 07 · Add-ons, Karpenter & the GitOps hand-offQ11. How do in-cluster add-ons installed by Argo CD learn AWS values like role ARNs or the interruption queue name?
Show answer
B. This 'GitOps bridge' keeps AWS identifiers generated by Terraform flowing into GitOps without duplicating them by hand.
From lesson 07 · Add-ons, Karpenter & the GitOps hand-offQ12. Why must Karpenter itself not run on nodes that Karpenter manages?
Show answer
B. The capacity manager must live on stable capacity it doesn't manage.
From lesson 07 · Add-ons, Karpenter & the GitOps hand-off