Playing with Cluster API
I have for a long time wanted to play around with Cluster API (CAPI) and I finally got around to test it at work recently. This post will mainly cover how to quickly get up and running using a local Kubernetes distribution as management cluster and provisioning an AWS EKS cluster with CAPI.
Bootstrapping
CAPI requires a CloudFormation stack to be provisioned and by using clusterawsadm we can first output a bootstrap config file for us to tweak and then create the stack.
Up front the bootstrap-config.yaml file doesn't need any tweaking, but it's good to have if we need to do changes at a later stage.
Local management cluster
For some reason I like minikube, but you can choose any other local Kubernetes distribution like k3s, kind etc.. Let's start the cluster.
We now need to initialize CAPI with an AWS provider on our local management cluster using clusterctl.
We set a bunch of feature flags that are good defaults and I find enablement of EXP_MACHINE_POOL absolutely essential for simplification.
- EXP_MACHINE_POOL enables the experimental Machine Pool feature, allowing you to manage groups of machines as a single unit with common configurations.
- EXP_CLUSTER_RESOURCE_SET enables experimental ClusterResourceSet support, which lets you automatically apply resources to clusters when they're created.
- CAPA_EKS_IAM enables IAM role management for EKS clusters, allowing Cluster API to create and configure IAM roles needed by EKS.
- CAPA_EKS_ADD_ROLES enables automatic addition of required IAM roles to worker nodes, ensuring they have proper permissions to join and operate in the EKS cluster
The above command will install cert-manager and the following Cluster API providers: cluster-api, bootstrap-kubeadm, control-plane-kubeadm and infrastructure-aws.
Provision workload cluster
Before we begin provisioning, an SSH key pair is required, so we'll provision one using the AWS CLI.
We are now ready to generate the manifests for our new cluster.
It is advised that you inspect the manifests before applying them.
We can now watch progress on workload cluster provisioning.
It will take some time to provision, so go grab something to drink. Once provisioned we can gain access to our new workload cluster using the following command.
Backup and restore
We can easily backup and restore using the following commands.
This means that our management cluster can potentially become ephemeral, assuming we can live without reconciliation.
Clean up
We can easily clean up. But it is important that we wait for the CAPI controllers to clean up AWS resources and that takes time.