Implementing Amazon EKS: From Zero to Deploy · Part 1 of 6
Implementing Amazon Elastic Kubernetes Service: From Zero to Deploy (Part 1/6)
Amazon Elastic Kubernetes Service (Amazon EKS) is a fully managed Kubernetes service on AWS. With it, customers such as Intel…
Keywords

Amazon Elastic Kubernetes Service (Amazon EKS) is a fully managed Kubernetes service on AWS. With it, customers such as Intel, Snap, Intuit, GoDaddy and many other companies run their most sensitive and mission-critical applications thanks to its security, reliability and scalability. In this series of posts we will see how to implement Amazon EKS from scratch all the way to deploying an application. The topics we will cover:
- Part 1 — Configuring a cluster in EKS
- Part 2 — Configuring node-groups in EKS
- Part 3 — Configuring IAM users as Masters
- Part 4 — Packaging from source code
- Part 5 — Publishing a container image to ECR
- Part 6 — Deploying to EKS from an image in ECR
For this series, the whole process will be carried out through the AWS CLI. So the first step is to install and configure the AWS CLI. More details on how to install and configure the AWS CLI can be found at https://docs.aws.amazon.com/pt_br/cli/latest/userguide/install-cliv2.html.
Part 1 — Configuring a cluster in EKS
First, let’s configure the IAM services for provisioning our EKS cluster.
- In IAM, create a role for EKS
- IAM > Roles > EKS
- Attach the policies “AmazonEKSClusterPolicy” and “AmazonEKSServicePolicy” and create a role named “EKSServiceRole”.
- Go to CloudFormation and create a stack named “EKS-VPC” to provision a VPC with subnets spread across 3 (three) different availability zones. Use the template available at https://amazon-eks.s3-us-west-2.amazonaws.com/cloudformation/2018-11-07/amazon-eks-vpc-sample.yaml
- The stack above will create: 1 (one) VPC, 3 (three) subnets and 1 (one) security group
Now we will create the cluster in EKS. The cluster will be named EKSDeepDive and must be associated with the role created in step [1]. We will create the cluster with “eksctl”. This step can take a few minutes — on average, between 10 and 15 minutes.
eksctl create cluster — region=us-east-1 — node-type=t2.small
If you get an error saying “_the target availability zone currently does not have sufficient capacity to support the cluster_”, then you need to specify the AZs to use, which are listed in the error output. For example:
eksctl create cluster — region=us-east-1 — node-type=t2.medium — zones=us-east-1a,us-east-1b,us-east-1c
Once the process is finished, let’s check that our cluster is running correctly. To do so, connect to your new EKS cluster using “kubectl”.
kubectl get nodes
Now let’s configure our EKS cluster and prepare an instance to serve as a bastion host.
Provision an EC2 instance with Amazon Linux 2 in the same VPC as the EKS cluster. To learn how to provision an EC2 instance with Amazon Linux, see https://docs.aws.amazon.com/pt_br/AWSEC2/latest/UserGuide/EC2_GetStarted.html.
After provisioning the EC2 instance, let’s configure the Kubernetes tooling so we can manage our cluster. We’ll set up kubectl on the instance to manage the EKS cluster.
mkdir $HOME/bin
curl -o kubectl https://amazon-eks.s3-us-west-2.amazonaws.com/\1.12.10/2019-08-14/bin/linux/amd64/kubectl
chmod +x ./kubectl
cp ./kubectl $HOME/bin/kubectl
export PATH=$HOME/bin:$PATH
echo ‘export PATH=$HOME/bin:$PATH’ >> ~/.bashrc
kubectl version — client
Now let’s configure the IAM services for cluster authentication. To do that, we’ll install aws-iam-authenticator.
mkdir $HOME/bin
curl -o aws-iam-authenticator https://amazon-eks.s3-us-west-2.amazonaws.com/\1.10.3/2018-07-26/bin/linux/amd64/\aws-iam-authenticator
chmod +x ./aws-iam-authenticator
cp ./aws-iam-authenticator $HOME/bin
export PATH=$HOME/bin:$PATH
echo ‘export PATH=$HOME/bin:$PATH’ >> ~/.bashrc
aws-iam-authenticator help
With that done, let’s configure kubectl to manage and control EKS.
curl -O https://bootstrap.pypa.io/get-pip.py
python get-pip.py — user
pip install awscli — upgrade — user
export PATH=$HOME/.local/bin:$PATH
echo ‘export PATH=$HOME/.local/bin:$PATH’ >> ~/.bashrc
aws configure
aws eks update-kubeconfig — name EKSDeepDive
kubectl config view
kubectl get svc
kubectl cluster-info
Done! Your EKS cluster should now be running.
In the next posts, we will cover:
- Part 2 — Configuring node-groups in EKS
- Part 3 — Configuring IAM users as Masters
- Part 4 — Packaging from source code
- Part 5 — Publishing a container image to ECR
- Part 6 — Deploying to EKS from an image in ECR
See you then! =)
Comments
Every comment is moderated before it appears here. Nothing is published automatically.
Loading…