View a markdown version of this page

EksAccessEntry - AWS Batch

EksAccessEntry

Configures whether AWS Batch manages an Amazon EKS access entry on the cluster for the compute environment. For information on how the fields interact with the cluster's authenticationMode and with other compute environments that share the cluster, see Amazon EKS access entry authentication in the AWS Batch User Guide.

Note

Setting desiredState=ENABLED on a single compute environment does not guarantee that AWS Batch creates an access entry, and setting desiredState=DISABLED on a single compute environment does not guarantee that AWS Batch deletes one. AWS Batch compares the desiredState across all compute environments that target the same cluster. The AWS Batch-managed access entry is created only when all compute environments have desiredState=ENABLED, and deleted only when all have desiredState=DISABLED. If you have multiple compute environments on the same cluster, set desiredState consistently across all of them to avoid uncertainty. For more information, see Reconciling desiredState across compute environments in the AWS Batch User Guide.

Contents

desiredState

The desired access entry state for the compute environment. Valid values:

ENABLED

AWS Batch manages an access entry on the cluster for the compute environment.

DISABLED

AWS Batch deletes the AWS Batch-managed access entry for the cluster. This value is rejected if the cluster's authenticationMode is API, because such a cluster doesn't support the aws-auth ConfigMap.

INHERIT_FROM_CLUSTER

AWS Batch defers to the cluster's current access entry status. On a cluster whose authentication mode is API, AWS Batch creates and manages an access entry. On a cluster whose authentication mode is API_AND_CONFIG_MAP or CONFIG_MAP, AWS Batch neither adds nor removes an access entry.

Type: String

Valid Values: ENABLED | DISABLED | INHERIT_FROM_CLUSTER

Required: Yes

status

The observed state of the access entry on the cluster. ACTIVE means that an access entry for the compute environment exists on the cluster and takes precedence over the aws-auth ConfigMap. INACTIVE means that no AWS Batch-managed access entry is present. This is a read-only field returned by DescribeComputeEnvironments.

Type: String

Valid Values: ACTIVE | INACTIVE

Required: No

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: