Class Cluster
- All Implemented Interfaces:
- IResource,- IConnectable,- ICluster,- software.amazon.jsii.JsiiSerializable,- software.constructs.IConstruct,- software.constructs.IDependable
- Direct Known Subclasses:
- FargateCluster
This is a fully managed cluster of API Servers (control-plane) The user is still required to create the worker nodes.
Example:
 import software.amazon.awscdk.cdk.lambdalayer.kubectl.v33.KubectlV33Layer;
 // or
 Vpc vpc;
 Cluster.Builder.create(this, "MyCluster")
         .kubectlMemory(Size.gibibytes(4))
         .version(KubernetesVersion.V1_33)
         .kubectlLayer(new KubectlV33Layer(this, "kubectl"))
         .build();
 Cluster.fromClusterAttributes(this, "MyCluster", ClusterAttributes.builder()
         .kubectlMemory(Size.gibibytes(4))
         .vpc(vpc)
         .clusterName("cluster-name")
         .build());
 - 
Nested Class SummaryNested ClassesNested classes/interfaces inherited from class software.amazon.jsii.JsiiObjectsoftware.amazon.jsii.JsiiObject.InitializationModeNested classes/interfaces inherited from interface software.amazon.awscdk.services.eks.IClusterICluster.Jsii$Default, ICluster.Jsii$ProxyNested classes/interfaces inherited from interface software.constructs.IConstructsoftware.constructs.IConstruct.Jsii$DefaultNested classes/interfaces inherited from interface software.amazon.awscdk.IResourceIResource.Jsii$Default
- 
Field SummaryFields
- 
Constructor SummaryConstructorsModifierConstructorDescriptionprotectedCluster(software.amazon.jsii.JsiiObject.InitializationMode initializationMode) protectedCluster(software.amazon.jsii.JsiiObjectRef objRef) Cluster(software.constructs.Construct scope, String id, ClusterProps props) Initiates an EKS Cluster with the supplied arguments.
- 
Method SummaryModifier and TypeMethodDescriptionAdd nodes to this EKS cluster.addCdk8sChart(String id, software.constructs.Construct chart) Defines a CDK8s chart in this cluster.addCdk8sChart(String id, software.constructs.Construct chart, KubernetesManifestOptions options) Defines a CDK8s chart in this cluster.addFargateProfile(String id, FargateProfileOptions options) Adds a Fargate profile to this cluster.addHelmChart(String id, HelmChartOptions options) Defines a Helm chart in this cluster.addManifest(String id, Map<String, Object>... manifest) Defines a Kubernetes resource in this cluster.Add managed nodegroup to this Amazon EKS cluster.addNodegroupCapacity(String id, NodegroupOptions options) Add managed nodegroup to this Amazon EKS cluster.Creates a new service account with corresponding IAM Role (IRSA).addServiceAccount(String id, ServiceAccountOptions options) Creates a new service account with corresponding IAM Role (IRSA).voidconnectAutoScalingGroupCapacity(AutoScalingGroup autoScalingGroup, AutoScalingGroupOptions options) Connect capacity in the form of an existing AutoScalingGroup to the EKS cluster.static IClusterfromClusterAttributes(software.constructs.Construct scope, String id, ClusterAttributes attrs) Import an existing cluster.An IAM role with administrative permissions to create or update the cluster.The ALB Controller construct defined for this cluster.The authentication mode for the Amazon EKS cluster.Lazily creates the AwsAuth resource, which manages AWS authentication mapping.An AWS Lambda layer that contains theawsCLI.The AWS generated ARN for the Cluster resource.The certificate-authority-data for your cluster.Amazon Resource Name (ARN) or alias of the customer master key (CMK).The endpoint URL for the Cluster.A security group to associate with the Cluster Handler's Lambdas.The Name of the created EKS Cluster.If this cluster is kubectl-enabled, returns the OpenID Connect issuer.If this cluster is kubectl-enabled, returns the OpenID Connect issuer url.The cluster security group that was created by Amazon EKS for the cluster.The id of the cluster security group that was created by Amazon EKS for the cluster.Manages connection rules (Security Group Rules) for the cluster.The auto scaling group that hosts the default capacity for this cluster.The node group that hosts the default capacity for this cluster.Retrieves the EKS Pod Identity Agent addon for the EKS cluster.getIngressLoadBalancerAddress(String ingressName) Fetch the load balancer address of an ingress backed by a load balancer.getIngressLoadBalancerAddress(String ingressName, IngressLoadBalancerAddressOptions options) Fetch the load balancer address of an ingress backed by a load balancer.Specify which IP family is used to assign Kubernetes pod and service IP addresses.Custom environment variables when runningkubectlagainst this cluster.An IAM role that can perform kubectl operations against this cluster.An AWS Lambda layer that includeskubectlandhelm.The amount of memory allocated to the kubectl provider's lambda function.Subnets to host thekubectlcompute resources.An IAM role that can perform kubectl operations against this cluster.A security group to use forkubectlexecution.The AWS Lambda layer that contains the NPM dependencyproxy-agent.AnOpenIdConnectProviderresource associated with this cluster, and which can be used to link this cluster to AWS IAM.getPrune()Determines if Kubernetes resources can be pruned automatically.getRole()IAM role assumed by the EKS Control Plane.getServiceLoadBalancerAddress(String serviceName) Fetch the load balancer address of a service of type 'LoadBalancer'.getServiceLoadBalancerAddress(String serviceName, ServiceLoadBalancerAddressOptions options) Fetch the load balancer address of a service of type 'LoadBalancer'.getVpc()The VPC in which this Cluster was created.voidgrantAccess(String id, String principal, List<IAccessPolicy> accessPolicies) Grants the specified IAM principal access to the EKS cluster based on the provided access policies.Methods inherited from class software.amazon.awscdk.ResourceapplyRemovalPolicy, generatePhysicalName, getEnv, getPhysicalName, getResourceArnAttribute, getResourceNameAttribute, getStack, isOwnedResource, isResourceMethods inherited from class software.constructs.ConstructgetNode, isConstruct, toStringMethods inherited from class software.amazon.jsii.JsiiObjectjsiiAsyncCall, jsiiAsyncCall, jsiiCall, jsiiCall, jsiiGet, jsiiGet, jsiiSet, jsiiStaticCall, jsiiStaticCall, jsiiStaticGet, jsiiStaticGet, jsiiStaticSet, jsiiStaticSetMethods inherited from class java.lang.Objectclone, equals, finalize, getClass, hashCode, notify, notifyAll, wait, wait, waitMethods inherited from interface software.amazon.awscdk.services.eks.IClustergetKubectlProviderMethods inherited from interface software.constructs.IConstructgetNodeMethods inherited from interface software.amazon.awscdk.IResourceapplyRemovalPolicy, getEnv, getStackMethods inherited from interface software.amazon.jsii.JsiiSerializable$jsii$toJson
- 
Field Details- 
PROPERTY_INJECTION_IDUniquely identifies this class.
 
- 
- 
Constructor Details- 
Clusterprotected Cluster(software.amazon.jsii.JsiiObjectRef objRef) 
- 
Clusterprotected Cluster(software.amazon.jsii.JsiiObject.InitializationMode initializationMode) 
- 
Cluster@Stability(Stable) public Cluster(@NotNull software.constructs.Construct scope, @NotNull String id, @NotNull ClusterProps props) Initiates an EKS Cluster with the supplied arguments.- Parameters:
- scope- a Construct, most likely a cdk.Stack created. This parameter is required.
- id- the id of the Construct to create. This parameter is required.
- props- properties in the IClusterProps interface. This parameter is required.
 
 
- 
- 
Method Details- 
fromClusterAttributes@Stability(Stable) @NotNull public static ICluster fromClusterAttributes(@NotNull software.constructs.Construct scope, @NotNull String id, @NotNull ClusterAttributes attrs) Import an existing cluster.- Parameters:
- scope- the construct scope, in most cases 'this'. This parameter is required.
- id- the id or name to import as. This parameter is required.
- attrs- the cluster properties to use for importing information. This parameter is required.
 
- 
addAutoScalingGroupCapacity@Stability(Stable) @NotNull public AutoScalingGroup addAutoScalingGroupCapacity(@NotNull String id, @NotNull AutoScalingGroupCapacityOptions options) Add nodes to this EKS cluster.The nodes will automatically be configured with the right VPC and AMI for the instance type and Kubernetes version. Note that if you specify updateType: RollingUpdateorupdateType: ReplacingUpdate, your nodes might be replaced at deploy time without notice in case the recommended AMI for your machine image type has been updated by AWS. The default behavior forupdateTypeisNone, which means only new instances will be launched using the new AMI.Spot instances will be labeled lifecycle=Ec2Spotand tainted withPreferNoSchedule. In addition, the spot interrupt handler daemon will be installed on all spot instances to handle EC2 Spot Instance Termination Notices.- Parameters:
- id- This parameter is required.
- options- This parameter is required.
 
- 
addCdk8sChart@Stability(Stable) @NotNull public KubernetesManifest addCdk8sChart(@NotNull String id, @NotNull software.constructs.Construct chart, @Nullable KubernetesManifestOptions options) Defines a CDK8s chart in this cluster.- Specified by:
- addCdk8sChartin interface- ICluster
- Parameters:
- id- logical id of this chart. This parameter is required.
- chart- the cdk8s chart. This parameter is required.
- options-
- Returns:
- a KubernetesManifestconstruct representing the chart.
 
- 
addCdk8sChart@Stability(Stable) @NotNull public KubernetesManifest addCdk8sChart(@NotNull String id, @NotNull software.constructs.Construct chart) Defines a CDK8s chart in this cluster.- Specified by:
- addCdk8sChartin interface- ICluster
- Parameters:
- id- logical id of this chart. This parameter is required.
- chart- the cdk8s chart. This parameter is required.
- Returns:
- a KubernetesManifestconstruct representing the chart.
 
- 
addFargateProfile@Stability(Stable) @NotNull public FargateProfile addFargateProfile(@NotNull String id, @NotNull FargateProfileOptions options) Adds a Fargate profile to this cluster.- Parameters:
- id- the id of this profile. This parameter is required.
- options- profile options. This parameter is required.
- See Also:
 
- 
addHelmChart@Stability(Stable) @NotNull public HelmChart addHelmChart(@NotNull String id, @NotNull HelmChartOptions options) Defines a Helm chart in this cluster.- Specified by:
- addHelmChartin interface- ICluster
- Parameters:
- id- logical id of this chart. This parameter is required.
- options- options of this chart. This parameter is required.
- Returns:
- a HelmChartconstruct
 
- 
addManifest@Stability(Stable) @NotNull public KubernetesManifest addManifest(@NotNull String id, @NotNull Map<String, Object>... manifest) Defines a Kubernetes resource in this cluster.The manifest will be applied/deleted using kubectl as needed. - Specified by:
- addManifestin interface- ICluster
- Parameters:
- id- logical id of this manifest. This parameter is required.
- manifest- a list of Kubernetes resource specifications. This parameter is required.
- Returns:
- a KubernetesResourceobject.
 
- 
addNodegroupCapacity@Stability(Stable) @NotNull public Nodegroup addNodegroupCapacity(@NotNull String id, @Nullable NodegroupOptions options) Add managed nodegroup to this Amazon EKS cluster.This method will create a new managed nodegroup and add into the capacity. - Parameters:
- id- The ID of the nodegroup. This parameter is required.
- options- options for creating a new nodegroup.
- See Also:
 
- 
addNodegroupCapacityAdd managed nodegroup to this Amazon EKS cluster.This method will create a new managed nodegroup and add into the capacity. - Parameters:
- id- The ID of the nodegroup. This parameter is required.
- See Also:
 
- 
addServiceAccount@Stability(Stable) @NotNull public ServiceAccount addServiceAccount(@NotNull String id, @Nullable ServiceAccountOptions options) Creates a new service account with corresponding IAM Role (IRSA).- Specified by:
- addServiceAccountin interface- ICluster
- Parameters:
- id- This parameter is required.
- options-
 
- 
addServiceAccountCreates a new service account with corresponding IAM Role (IRSA).- Specified by:
- addServiceAccountin interface- ICluster
- Parameters:
- id- This parameter is required.
 
- 
connectAutoScalingGroupCapacity@Stability(Stable) public void connectAutoScalingGroupCapacity(@NotNull AutoScalingGroup autoScalingGroup, @NotNull AutoScalingGroupOptions options) Connect capacity in the form of an existing AutoScalingGroup to the EKS cluster.The AutoScalingGroup must be running an EKS-optimized AMI containing the /etc/eks/bootstrap.sh script. This method will configure Security Groups, add the right policies to the instance role, apply the right tags, and add the required user data to the instance's launch configuration. Spot instances will be labeled lifecycle=Ec2Spotand tainted withPreferNoSchedule. If kubectl is enabled, the spot interrupt handler daemon will be installed on all spot instances to handle EC2 Spot Instance Termination Notices.Prefer to use addAutoScalingGroupCapacityif possible.- Specified by:
- connectAutoScalingGroupCapacityin interface- ICluster
- Parameters:
- autoScalingGroup- [disable-awslint:ref-via-interface]. This parameter is required.
- options- options for adding auto scaling groups, like customizing the bootstrap script. This parameter is required.
- See Also:
 
- 
getIngressLoadBalancerAddress@Stability(Stable) @NotNull public String getIngressLoadBalancerAddress(@NotNull String ingressName, @Nullable IngressLoadBalancerAddressOptions options) Fetch the load balancer address of an ingress backed by a load balancer.- Parameters:
- ingressName- The name of the ingress. This parameter is required.
- options- Additional operation options.
 
- 
getIngressLoadBalancerAddress@Stability(Stable) @NotNull public String getIngressLoadBalancerAddress(@NotNull String ingressName) Fetch the load balancer address of an ingress backed by a load balancer.- Parameters:
- ingressName- The name of the ingress. This parameter is required.
 
- 
getServiceLoadBalancerAddress@Stability(Stable) @NotNull public String getServiceLoadBalancerAddress(@NotNull String serviceName, @Nullable ServiceLoadBalancerAddressOptions options) Fetch the load balancer address of a service of type 'LoadBalancer'.- Parameters:
- serviceName- The name of the service. This parameter is required.
- options- Additional operation options.
 
- 
getServiceLoadBalancerAddress@Stability(Stable) @NotNull public String getServiceLoadBalancerAddress(@NotNull String serviceName) Fetch the load balancer address of a service of type 'LoadBalancer'.- Parameters:
- serviceName- The name of the service. This parameter is required.
 
- 
grantAccess@Stability(Stable) public void grantAccess(@NotNull String id, @NotNull String principal, @NotNull List<IAccessPolicy> accessPolicies) Grants the specified IAM principal access to the EKS cluster based on the provided access policies.This method creates an AccessEntryconstruct that grants the specified IAM principal the access permissions defined by the providedIAccessPolicyarray. This allows the IAM principal to perform the actions permitted by the access policies within the EKS cluster.- Parameters:
- id-- The ID of the AccessEntryconstruct to be created.
 
- The ID of the 
- principal-- The IAM principal (role or user) to be granted access to the EKS cluster.
 
- accessPolicies-- An array of IAccessPolicyobjects that define the access permissions to be granted to the IAM principal.
 
- An array of 
 
- 
getAdminRoleAn IAM role with administrative permissions to create or update the cluster.This role also has systems:masterpermissions.
- 
getAwsAuthLazily creates the AwsAuth resource, which manages AWS authentication mapping.
- 
getClusterArnThe AWS generated ARN for the Cluster resource.For example, arn:aws:eks:us-west-2:666666666666:cluster/prod- Specified by:
- getClusterArnin interface- ICluster
 
- 
getClusterCertificateAuthorityDataThe certificate-authority-data for your cluster.- Specified by:
- getClusterCertificateAuthorityDatain interface- ICluster
 
- 
getClusterEncryptionConfigKeyArnAmazon Resource Name (ARN) or alias of the customer master key (CMK).- Specified by:
- getClusterEncryptionConfigKeyArnin interface- ICluster
 
- 
getClusterEndpointThe endpoint URL for the Cluster.This is the URL inside the kubeconfig file to use with kubectl For example, https://5E1D0CEXAMPLEA591B746AFC5AB30262---yl4---us-west-2---eks.amazonaws.com.rproxy.govskope.ca- Specified by:
- getClusterEndpointin interface- ICluster
 
- 
getClusterNameThe Name of the created EKS Cluster.- Specified by:
- getClusterNamein interface- ICluster
 
- 
getClusterOpenIdConnectIssuerIf this cluster is kubectl-enabled, returns the OpenID Connect issuer.This is because the values is only be retrieved by the API and not exposed by CloudFormation. If this cluster is not kubectl-enabled (i.e. uses the stock CfnCluster), this isundefined.
- 
getClusterOpenIdConnectIssuerUrlIf this cluster is kubectl-enabled, returns the OpenID Connect issuer url.This is because the values is only be retrieved by the API and not exposed by CloudFormation. If this cluster is not kubectl-enabled (i.e. uses the stock CfnCluster), this isundefined.
- 
getClusterSecurityGroupThe cluster security group that was created by Amazon EKS for the cluster.- Specified by:
- getClusterSecurityGroupin interface- ICluster
 
- 
getClusterSecurityGroupIdThe id of the cluster security group that was created by Amazon EKS for the cluster.- Specified by:
- getClusterSecurityGroupIdin interface- ICluster
 
- 
getConnectionsManages connection rules (Security Group Rules) for the cluster.- Specified by:
- getConnectionsin interface- IConnectable
 
- 
getOpenIdConnectProviderAnOpenIdConnectProviderresource associated with this cluster, and which can be used to link this cluster to AWS IAM.A provider will only be defined if this property is accessed (lazy initialization). - Specified by:
- getOpenIdConnectProviderin interface- ICluster
 
- 
getPruneDetermines if Kubernetes resources can be pruned automatically.
- 
getRoleIAM role assumed by the EKS Control Plane.
- 
getVpcThe VPC in which this Cluster was created.
- 
getAlbControllerThe ALB Controller construct defined for this cluster.Will be undefined if albControllerwasn't configured.
- 
getAuthenticationModeThe authentication mode for the Amazon EKS cluster.The authentication mode determines how users and applications authenticate to the Kubernetes API server. Default: CONFIG_MAP. - Specified by:
- getAuthenticationModein interface- ICluster
 
- 
getAwscliLayerAn AWS Lambda layer that contains theawsCLI.If not defined, a default layer will be used containing the AWS CLI 1.x. - Specified by:
- getAwscliLayerin interface- ICluster
 
- 
getClusterHandlerSecurityGroupA security group to associate with the Cluster Handler's Lambdas.The Cluster Handler's Lambdas are responsible for calling AWS's EKS API. Requires placeClusterHandlerInVpcto be set to true.Default: - No security group. - Specified by:
- getClusterHandlerSecurityGroupin interface- ICluster
 
- 
getDefaultCapacityThe auto scaling group that hosts the default capacity for this cluster.This will be undefinedif thedefaultCapacityTypeis notEC2ordefaultCapacityTypeisEC2but default capacity is set to 0.
- 
getDefaultNodegroupThe node group that hosts the default capacity for this cluster.This will be undefinedif thedefaultCapacityTypeisEC2ordefaultCapacityTypeisNODEGROUPbut default capacity is set to 0.
- 
getEksPodIdentityAgentRetrieves the EKS Pod Identity Agent addon for the EKS cluster.The EKS Pod Identity Agent is responsible for managing the temporary credentials used by pods in the cluster to access AWS resources. It runs as a DaemonSet on each node and provides the necessary credentials to the pods based on their associated service account. - Specified by:
- getEksPodIdentityAgentin interface- ICluster
 
- 
getIpFamilySpecify which IP family is used to assign Kubernetes pod and service IP addresses.Default: - IpFamily.IP_V4 - Specified by:
- getIpFamilyin interface- ICluster
- See Also:
 
- 
getKubectlEnvironmentCustom environment variables when runningkubectlagainst this cluster.- Specified by:
- getKubectlEnvironmentin interface- ICluster
 
- 
getKubectlLambdaRoleAn IAM role that can perform kubectl operations against this cluster.The role should be mapped to the system:mastersKubernetes RBAC role.This role is directly passed to the lambda handler that sends Kube Ctl commands to the cluster. Default: - if not specified, the default role created by a lambda function will be used. - Specified by:
- getKubectlLambdaRolein interface- ICluster
 
- 
getKubectlLayerAn AWS Lambda layer that includeskubectlandhelm.- Specified by:
- getKubectlLayerin interface- ICluster
 
- 
getKubectlMemoryThe amount of memory allocated to the kubectl provider's lambda function.- Specified by:
- getKubectlMemoryin interface- ICluster
 
- 
getKubectlPrivateSubnetsSubnets to host thekubectlcompute resources.Default: - If not specified, the k8s endpoint is expected to be accessible publicly. - Specified by:
- getKubectlPrivateSubnetsin interface- ICluster
 
- 
getKubectlRoleAn IAM role that can perform kubectl operations against this cluster.The role should be mapped to the system:mastersKubernetes RBAC role.- Specified by:
- getKubectlRolein interface- ICluster
 
- 
getKubectlSecurityGroupA security group to use forkubectlexecution.Default: - If not specified, the k8s endpoint is expected to be accessible publicly. - Specified by:
- getKubectlSecurityGroupin interface- ICluster
 
- 
getOnEventLayerThe AWS Lambda layer that contains the NPM dependencyproxy-agent.If undefined, a SAR app that contains this layer will be used. - Specified by:
- getOnEventLayerin interface- ICluster
 
 
-