The module lifecycle stage: General Availability

An example of the AWSInstanceClass custom resource

Below is a simple example of custom resource AWSInstanceClass configuration:

apiVersion: deckhouse.io/v1
kind: AWSInstanceClass
metadata:
  name: worker
spec:
  instanceType: t3.large
  ami: ami-040a1551f9c9d11ad
  diskSizeGb: 15
  diskType:  gp2

LoadBalancer

Service object Annotations

The following parameters are supported in addition to the existing upstream ones:

  1. service.beta.kubernetes.io/aws-load-balancer-type — if it has the none value, then the target group will only be created (without any LoadBalancer).
  2. service.beta.kubernetes.io/aws-load-balancer-backend-protocol — this parameter is used together with service.beta.kubernetes.io/aws-load-balancer-type: none:
    • Possible values:
      • tcp (default);
      • tls;
      • http;
      • https.
    • Caution! The cloud-controller-manager (CCM) will try to recreate the target group in response to changes in this field. If the target group has NLB or ALB attached to it, the CCM will fail to delete it and get stuck in this state forever. You have to manually disconnect NLB or ALB from the target group.

Configuring the load balancer if Ingress nodes are not available in all zones

Set the following annotation for the Service object: service.beta.kubernetes.io/aws-load-balancer-subnets: subnet-foo, subnet-bar.

You can get current subnets for a particular installation as follows:

d8 k -n d8-system exec svc/deckhouse-leader -c deckhouse -- deckhouse-controller module values cloud-provider-aws -o json \
| jq -r '.cloudProviderAws.internal.zoneToSubnetIdMap'