Architecture and access
Provisioning
07 / 69

Use eksctl to learn and iterate; use infrastructure as code for anything that lasts.

All three create the same cluster. The difference is repeatability, review and how the cluster fits with the rest of your AWS estate.

eksctl: quick start
$ eksctl create cluster --name shop-eu --region eu-west-1 \
    --version 1.31 --nodegroup-name std --nodes 3
... 12 minutes later
EKS cluster "shop-eu" in "eu-west-1" region is ready
$ aws eks update-kubeconfig --name shop-eu --region eu-west-1
$ kubectl get nodes
Terraform (terraform-aws-modules/eks)
module "eks" {
  source          = "terraform-aws-modules/eks/aws"
  cluster_name    = "shop-eu"
  subnet_ids      = module.vpc.private_subnets
  authentication_mode = "API"
}

eksctl

Fast and approachable: creates the VPC, IAM roles and node group from a command or a ClusterConfig file. Great for labs and short-lived clusters.

Terraform or CloudFormation

Reviewable, repeatable, and part of the same codebase as the VPC, IAM and databases. Preferred for production.

Console

Useful to explore options. Avoid for anything you must reproduce, because it leaves no code to review.

Decide once, document it

Authentication mode, endpoint access, secrets encryption and logging are easier to set at creation than to retrofit.