aws-samples / aws-samples/eks-workshop-v2

Re-architect workshop infrastructure

Open
#1,521 1 comment 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
HCL
Stars
626
Forks
613
Avg merge
2d 7h
Merged PRs (30d)
9

Description

### What would you like to be added?

This proposal would re-design the workshop infrastructure. The main changes would be:

## VPC re-architecture

The IDE VPC will be expanded to be able to support an EKS cluster. We'll use the eksctl VPC design as a template in terms of subnets etc. The main change would be to make sure only private subnets are tagged for Karpenter.

## IDE updates

The VPC ID should be injected in to the IDEs via `bashrc.d` mechanism. Other details like subnets should be looked up "just in time" when needed.

## IaC updates

The eksctl and Terraform cluster configuration will be changed to use the IDE VPC instead of creating their own.

The eksctl configuration is already templated for the cluster name and region, this will be expanded to include the VPC details.

The Terraform can just look up the VPC by tags.

```hcl
data "aws_vpc" "selected" {
tags = [...]
}
```

This change would be considered "breaking" and will need a full announcement and migration instructions.

## Content updates

All relevant content should be updated to make endpoints private, which includes:

1. The sample application when its deployed with a load balancer or ingress
2. 3rd party tools like ArgoCD and Kubecost

Content should be modified to note that we're creating internal load balancers.

## Development & tests

Currently the local development experience assumes that endpoints like load balancers are public. Consideration will need to be made for how making everything private can be accounted for.

### Why is this needed?

Ideally the sample application and other components like ArgoCD and Grafana are not exposed over the public Internet. This change would allow us to use internal load balancers. Using port forwarding through kubectl is not a great user experience and is error-prone.

Contributor guide

Open the contributing guide

Research direction

Start with the eksctl and Terraform cluster configurations and the IDE bashrc.d mechanism mentioned in the proposal. Then review the sample application, ArgoCD, Kubecost, and Grafana content plus the local development and test assumptions about public endpoints. Done means the shared IDE VPC supports the cluster, endpoints are private, content and migration instructions are updated, and local development remains accounted for.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, kubernetes, shell, terraform
Domain
cloud, devops, documentation, infrastructure, networking, testing-qa
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.