我想設定一個 EKS 集群,使其他 IAM 用戶能夠連接和修改該集群。為此,AWS 建議修補配置映射,我這樣做了。現在我想使用 terraform 啟用相同的“功能”。
我使用 terraforms EKS 提供程式并閱讀“由于過多的工具...”部分中的檔案,基本上身份驗證取決于我自己。
現在我使用Terraform Kubernetes 提供程式來更新這個配置圖:
resource "kubernetes_config_map" "aws_auth" {
depends_on = [module.eks.cluster_id]
metadata {
name = "aws-auth"
namespace = "kube-system"
}
data = THATS_MY_UPDATED_CONFIG
}
但不成功并得到以下錯誤:
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: 2022/01/07 15:49:55 [DEBUG] Kubernetes API Response Details:
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: ---[ RESPONSE ]--------------------------------------
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: HTTP/2.0 409 Conflict
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: Content-Length: 206
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: Audit-Id: 15....
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: Cache-Control: no-cache, private
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: Content-Type: application/json
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: Date: Fri, 07 Jan 2022 14:49:55 GMT
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: X-Kubernetes-Pf-Flowschema-Uid: f43...
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: X-Kubernetes-Pf-Prioritylevel-Uid: 0054...
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5:
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: {
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: "kind": "Status",
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: "apiVersion": "v1",
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: "metadata": {},
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: "status": "Failure",
2022-01-07T15:49:55.732 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: "message": "configmaps \"aws-auth\" already exists",
2022-01-07T15:49:55.733 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: "reason": "AlreadyExists",
2022-01-07T15:49:55.733 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: "details": {
2022-01-07T15:49:55.733 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: "name": "aws-auth",
2022-01-07T15:49:55.733 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: "kind": "configmaps"
2022-01-07T15:49:55.733 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: },
2022-01-07T15:49:55.733 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: "code": 409
2022-01-07T15:49:55.733 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: }
2022-01-07T15:49:55.733 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5:
2022-01-07T15:49:55.733 0100 [DEBUG] provider.terraform-provider-kubernetes_v2.7.1_x5: -----------------------------------------------------
2022-01-07T15:49:55.775 0100 [ERROR] vertex "module.main.module.eks.kubernetes_config_map.aws_auth" error: configmaps "aws-auth" already exists
?
│ Error: configmaps "aws-auth" already exists
│
│ with module.main.module.eks.kubernetes_config_map.aws_auth,
│ on ../../modules/eks/eks-iam-map-users.tf line 44, in resource "kubernetes_config_map" "aws_auth":
│ 44: resource "kubernetes_config_map" "aws_auth" {
│
?
這似乎是一個有爭議的問題,每個使用 EKS 和 Terraform 的人都應該擁有它——我問自己如何解決這個問題?在相關的問題,我是接近....我多少有些失落,任何人有一個想法?
我使用以下版本:
terraform {
required_providers {
# https://registry.terraform.io/providers/hashicorp/aws/latest
aws = {
source = "hashicorp/aws"
version = "~> 3.70"
}
# https://registry.terraform.io/providers/hashicorp/kubernetes/latest
kubernetes = {
source = "hashicorp/kubernetes"
version = "~> 2.7.1"
}
required_version = ">= 1.1.2"
}
...
module "eks" {
source = "terraform-aws-modules/eks/aws"
version = "18.0.3"
...
uj5u.com熱心網友回復:
我使用 17.24.0,但不知道 18.0.3 有什么新功能。
就我而言,我遵循以下示例:https : //github.com/terraform-aws-modules/terraform-aws-eks/blob/v17.24.0/examples/complete/main.tf
我的 main.tf
locals {
eks_map_roles = []
eks_map_users = []
}
data "aws_eks_cluster" "cluster" {
name = module.eks.cluster_id
}
data "aws_eks_cluster_auth" "cluster" {
name = module.eks.cluster_id
}
provider "kubernetes" {
host = data.aws_eks_cluster.cluster.endpoint
cluster_ca_certificate = base64decode(data.aws_eks_cluster.cluster.certificate_authority[0].data)
token = data.aws_eks_cluster_auth.cluster.token
}
module "eks" {
source = "..."
...
eks_map_roles = local.eks_map_roles
eks_map_users = local.eks_map_users
...
}
要添加其他用戶,您可以遵循以下檔案:https : //aws.amazon.com/premiumsupport/knowledge-center/eks-api-server-unauthorized-error/
我認為您應該添加角色(不要忘記洗掉路徑)。
轉載請註明出處,本文鏈接:https://www.uj5u.com/houduan/406326.html
標籤:
