Implementing Amazon EKS: From Zero to Deploy · Part 2 of 6
Implementing Amazon Elastic Kubernetes Service: From Zero to Deploy (Part 2/6)
Amazon Elastic Kubernetes Service (Amazon EKS) is a fully managed Kubernetes service on AWS. With it, customers such as Intel…
Keywords

Amazon Elastic Kubernetes Service (Amazon EKS) is a fully managed Kubernetes service on AWS. With it, customers such as Intel, Snap, Intuit, GoDaddy and many other companies run their most sensitive and mission-critical applications thanks to its security, reliability and scalability. In this series of posts we will see how to implement Amazon EKS from scratch all the way to deploying an application. The topics we will cover:
- Part 1 — Configuring a cluster in EKS
- Part 2 — Configuring node-groups in EKS
- Part 3 — Configuring IAM users as Masters
- Part 4 — Packaging from source code
- Part 5 — Publishing a container image to ECR
- Part 6 — Deploying to EKS from an image in ECR
Continuing our series, today we will configure the node-groups in EKS.
Amazon EKS managed node groups (node-groups) automate the provisioning and lifecycle management of nodes (Amazon EC2 instances) for Kubernetes clusters on Amazon EKS. With Amazon EKS managed node groups, you don’t need to separately provision or register the Amazon EC2 instances that provide compute capacity to run your Kubernetes applications. You can create, update or terminate nodes for your cluster with a single operation. Nodes run using the latest Amazon EKS optimized AMIs in your AWS account. Node updates and terminations drain the nodes to ensure your applications remain available.
Part 2 — Configuring node-groups in EKS
CONFIGURING WORKER-NODES IN AWS EKS
- Provision a stack named EKS-Workernodes in CloudFormation to bring up the worker-nodes;
- Script available at https://amazon-eks.s3-us-west-2.amazonaws.com/cloudformation/2018-11-07/amazon-eks-nodegroup.yaml
- Select the EKS cluster EKSDeepDive
- Select the ClusterControlPlaneSecurityGroup;
- Select the EKS cluster’s VPC;
- In NodeGroupName, enter NodeGroup;
- Select the latest EKS-optimized Amazon Linux AMI: https://docs.aws.amazon.com/eks/latest/userguide/eks-optimized-ami.html;
- Attach a key pair if you want to SSH into a specific worker-node;
- Associate the EKS cluster’s VPC;
- Associate the subnets of the EKS cluster’s VPC;
- Configure the AWS IAM EKS Authenticator;
- curl -O https://amazon-eks.s3-us-west-2.amazonaws.com/\cloudformation/2018-11-07/aws-auth-cm.yaml
- Edit aws-auth-cm.yaml to set the Node Instance Role ARN returned as an Output of the CloudFormation stack
- kubectl apply -f aws-auth-cm.yaml
- kubectl get nodes — watch
CONFIGURING THE KUBERNETES DASHBOARD
- Install the Kubernetes Dashboard by going to https://github.com/kubernetes/dashboard
kubectl apply -f https://raw.githubusercontent.com/kubernetes/dashboard/v2.0.1/aio/deploy/recommended.yaml
- Install Heapster and InfluxDB for monitoring:
kubectl apply -f https://raw.githubusercontent.com/kubernetes/heapster/master/deploy/kube-config/influxdb/heapster.yaml
kubectl apply -f https://raw.githubusercontent.com/kubernetes/heapster/master/deploy/kube-config/influxdb/influxdb.yaml
kubectl apply -f https://raw.githubusercontent.com/kubernetes/heapster/master/deploy/kube-config/rbac/heapster-rbac.yaml
- By default, the Kubernetes Dashboard has many access restrictions. So you will need to create a user to access the Dashboard;
- Create the file eks-admin-service-account.yaml
apiVersion: v1
kind: ServiceAccount
metadata:
name: eks-admin
namespace: kube-system
- Create the file eks-admin-cluster-role-binding.yaml
apiVersion: rbac.authorization.k8s.io/v1beta1
kind: ClusterRoleBinding
metadata:
name: eks-admin
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: cluster-admin
subjects:
- kind: ServiceAccount
name: eks-admin
namespace: kube-system
- To access the Dashboard externally, you will need to configure a proxy service on the server. Alternatively, the Kubernetes Dashboard can be installed locally — following the previous steps. To start the Kubernetes proxy service:
- kubectl proxy — address 0.0.0.0 — accept-hosts ‘.*’ &
- To log in to the Kubernetes Dashboard, you will go to localhost:8001 and provide a token. To generate the token;
- Generating the token in JSON format
- aws-iam-authenticator -i EKSDeepDive token
- Generating the token in RAW format
- aws-iam-authenticator -i EKSDeepDive token | jq -r .status.token
In our next post, we will see how to configure IAM users as Masters for administering the cluster and the node-groups.
See you then! =)
Comments
Every comment is moderated before it appears here. Nothing is published automatically.
Loading…