Advanced EKS Cluster with Terraform Modules
terraform fmt -checkOverview
Section titled “Overview”Advanced EKS Terraform module layout with hardening edits.
What You Will Build
Section titled “What You Will Build”Architecture Diagram
Section titled “Architecture Diagram”Prerequisites
Section titled “Prerequisites”- Install or review: Terraform, EKS, VPC, Kubernetes, AWS.
- Use your own cloud account credentials and keep them out of commits.
- This project expects cloud resources, so verify budget alerts and cleanup first.
- Open the safety guide before running commands that create infrastructure.
Credentials And Cost Warning
Section titled “Credentials And Cost Warning”Cost risk is high. Cloud target: AWS. Cloud credentials needed: Yes. Always use your own account, never commit secrets, and confirm cleanup before creating paid infrastructure.
Step-By-Step Lab
Section titled “Step-By-Step Lab”Use this flow before you run commands:
- Read the cost and credential warning above.
- Review the validation, troubleshooting, cleanup, and portfolio proof sections below.
- Follow the original project guide preserved near the bottom of this page.
- Return to the validation and cleanup checks before you capture portfolio evidence.
Validation Checks
Section titled “Validation Checks”Run the project validation command before and after meaningful changes:
terraform fmt -checkTroubleshooting
Section titled “Troubleshooting”- Run
terraform fmt -checkfirst so local tooling issues are visible early. - If a command fails, check tool versions, working directory, and required environment variables.
- For cloud failures, confirm account identity, region, quotas, and least-privilege IAM.
Cleanup
Section titled “Cleanup”Cleanup is available or expected for this lab. Use the cleanup or destroy steps in the guide below, then confirm that local clusters, containers, cloud resources, buckets, state files, and CI secrets are no longer active.
Portfolio Proof
Section titled “Portfolio Proof”- Validation command output:
terraform fmt -check - Screenshot or terminal proof: Plan/apply evidence plus destroy proof
- Notes explaining what changed, what failed, and how you fixed it
- Cleanup evidence, especially for cloud or Kubernetes resources
Original Project Guide
Section titled “Original Project Guide”The original README content is preserved here for lab-specific commands and context. Headings are intentionally demoted so the page outline stays focused on the standard lab flow.
:loudspeaker: ᴛᴇʀʀᴀғᴏʀᴍ: ᴀʙᴏᴜᴛ ᴛʜɪs ᴘʀᴏᴊᴇᴄᴛ ᴍᴏᴅᴜʟᴇs
Section titled “:loudspeaker: ᴛᴇʀʀᴀғᴏʀᴍ: ᴀʙᴏᴜᴛ ᴛʜɪs ᴘʀᴏᴊᴇᴄᴛ ᴍᴏᴅᴜʟᴇs”Kubernetes, often abbreviated as “K8s” (because there are 8 letters between the “K” & “s” in Kubernetes), orchestrates containerized applications to run on a cluster of hosts. K8s also allocates storage and persistent volumes to running containers, provides automatic scaling, and works continuously to maintain the desired state of applications, providing resiliency.
Terraform is an extremely popular infrastructure provisioning tool among DevOps. EKS is managed K8S solution provided by AWS, which is widely used managed K8S platform by AWS consumers.
Separately, Kubernetes and Terraform are powerful and popular tools for DevOps operations. However, when you decide to use them together, you will see even more benefits for container cluster management!
:loudspeaker: ᴛᴇʀʀᴀғᴏʀᴍ: ᴡʜʏ ᴅᴇᴘʟᴏʏ ᴡɪᴛʜ ᴛᴇʀʀᴀғᴏʀᴍ?
Section titled “:loudspeaker: ᴛᴇʀʀᴀғᴏʀᴍ: ᴡʜʏ ᴅᴇᴘʟᴏʏ ᴡɪᴛʜ ᴛᴇʀʀᴀғᴏʀᴍ?”While you could use the built-in AWS provisioning (UI, CLI, CloudFormation) for EKS clusters, Terraform provides you with several benefits:
-
Terraform can be used to manage Kubernetes infrastructure, helping you to orchestrate your applications and run them at scale. This alleviates some of the challenges of running Kubernetes, including detecting configuration drift — planned & unplanned changes.
-
Terraform will create resources, it will also update & delete tracked resources without requiring inspection of the API.
-
Terraform understands dependency relationships between resources. For example, if an AWS Kubernetes cluster needs a specific VPC and subnet configurations, Terraform won’t attempt to create the cluster if the VPC and subnet failed to create with the proper configuration.
🛡️ 2026 DevSecOps Enhancements (What You Will Learn)
Section titled “🛡️ 2026 DevSecOps Enhancements (What You Will Learn)”This repository demonstrates a legacy method of providing AWS credentials to Terraform Cloud via static Access Keys. In a 2026 DevSecOps context, this represents a severe credential leakage risk.
Modern deployments utilize Dynamic Workload Identity (OIDC - OpenID Connect). By establishing an OIDC trust relationship between AWS IAM and Terraform Cloud, Terraform dynamically requests short-lived, ephemeral STS credentials to provision the cluster, entirely eliminating the need for hardcoded AWS_ACCESS_KEY_ID variables.
:loudspeaker: ᴛᴇʀʀᴀғᴏʀᴍ: ᴘʀᴇʀᴇǫᴜɪsɪᴛᴇs
Section titled “:loudspeaker: ᴛᴇʀʀᴀғᴏʀᴍ: ᴘʀᴇʀᴇǫᴜɪsɪᴛᴇs”For this tutorial, you will need:
-
AWS account
-
Terraform & Kubernetes installed on your IDE (I will be using VSCode)
-
AWS CLI installed and configured on your IDE
:loudspeaker: ᴛᴇʀʀᴀғᴏʀᴍ: ᴏᴜʀ ᴏʙᴊᴇᴄᴛɪᴠᴇ:
Section titled “:loudspeaker: ᴛᴇʀʀᴀғᴏʀᴍ: ᴏᴜʀ ᴏʙᴊᴇᴄᴛɪᴠᴇ:”-
Create an EKS cluster (capacity of 2).
-
Create a random string that allows 5 characters to build the cluster name.
-
They want to output the cluster name and the ip address of the containers in the cluster.
Lastly, all code should be in module blocks, not resource blocks.
Let’s get started — buckle up Chuck!!
Solid Defaults
Section titled “Solid Defaults”The example now keeps public EKS API access and demo node ingress behind variables instead of hard-coded open CIDRs:
terraform plan \ -var='cluster_endpoint_public_access_cidrs=["203.0.113.10/32"]' \ -var='admin_cidr_block=203.0.113.10/32'The sample Kubernetes deployment includes HTTP readiness/liveness probes, resource requests/limits, and a runtime default seccomp profile. The service selector matches the deployment labels so kubectl get endpoints terraform-project102 can resolve pods after the workload is created.
𝟷| sᴇᴛ ᴜᴘ ғɪʟᴇ sʏsᴛᴇᴍ
Section titled “𝟷| sᴇᴛ ᴜᴘ ғɪʟᴇ sʏsᴛᴇᴍ”First, clone my GitHub repository:
git clone https://github.com/harshhaareddy/eks-cluster-terraformChange into the directory to the folder shown below:
cd eks-cluster-terraform𝟸| ᴛᴇʀʀᴀғᴏʀᴍ ɪɴɪᴛ, ᴘʟᴀɴ & ᴀᴘᴘʟʏ
Section titled “𝟸| ᴛᴇʀʀᴀғᴏʀᴍ ɪɴɪᴛ, ᴘʟᴀɴ & ᴀᴘᴘʟʏ”After you have created the above files, the first step is to initialize the terraform backend by using the terraform init command. Next, you will run the terraform plan command to evaluate the Terraform configuration. Finally, you will run the command terraform apply to apply the configuration.
Also, run the following command to to retrieve the access credentials for your cluster and configure kubectl:
aws eks update-kubeconfig --name <EKS_CLUSTER_NAME> --region <REGION>Run kubectl commands to manage your cluster and deploy Kubernetes configurations to it.
𝟹| ᴛᴇʀʀᴀғᴏʀᴍ ᴄʟᴏᴜᴅ
Section titled “𝟹| ᴛᴇʀʀᴀғᴏʀᴍ ᴄʟᴏᴜᴅ”Navigate to the Terraform Cloud platform, choose your organization and create a new workspace.
Under Choose your workflow, select the version control workflow option. After you’ve selected your workflow, you’ll be directed to a different page where you will need to connect a version control provider. You will want to connect with your GitHub account and select the repo that you created in the first step.
From there, you will create our new Workspace:
Then you will set variables for our access keys and region. To get started, click Configure Variables followed by Add variable.
We will be inputting the below variables as Keys and then Value will be the password.
-
IMPORTANT: Click Sensitive for your key variables, as this will ensure your private information is not displayed.
⇥ AWS_ACCESS_KEY_ID ⇥ AWS_SECRET_ACCESS_KEY ⇥ AWS_DEFAULT_REGION ⇥ CONFIRM_DESTROY
𝟺| ʀᴜɴ ɴᴇᴡ ᴛᴇʀʀᴀғᴏʀᴍ ᴄʟᴏᴜᴅ ᴘʟᴀɴ
Section titled “𝟺| ʀᴜɴ ɴᴇᴡ ᴛᴇʀʀᴀғᴏʀᴍ ᴄʟᴏᴜᴅ ᴘʟᴀɴ”Let’s go things kicked off — click Start new run under the Actions tab.
Once you start your run, the next step will be to Plan & Apply. Your plan should finish pretty quickly and once it’s finished, you’ll be prompted to click Confirm & Apply.
From here, click the Apply finished box, scroll to the bottom and you’ll see the Outputs in TF Cloud:
Let’s pop to the AWS EC2 console and confirm that you have correctly setup your cluster. As you can see from the image below, everything looks great!
𝟻| ᴛᴇʀʀᴀғᴏʀᴍ ᴅᴇsᴛʀᴏʏ
Section titled “𝟻| ᴛᴇʀʀᴀғᴏʀᴍ ᴅᴇsᴛʀᴏʏ”Let’s destroy our infrastructure! Yay! Navigate back to the Terraform Cloud platform, and under settings click Destruction and Deletion. Click Queue destroy plan and select Confirm & Apply.
You’ve just deployed an EKS Cluster using Terraform Cloud CI/CD!
Section titled “You’ve just deployed an EKS Cluster using Terraform Cloud CI/CD!”
:biohazard: ᴄʀᴇᴅɪᴛs & ᴍᴏʀᴇ ᴀʙᴏᴜᴛ ʟɪᴋᴇ ᴛʜɪs ᴏʀ ғᴏʟʟᴏᴡ
Section titled “:biohazard: ᴄʀᴇᴅɪᴛs & ᴍᴏʀᴇ ᴀʙᴏᴜᴛ ʟɪᴋᴇ ᴛʜɪs ᴏʀ ғᴏʟʟᴏᴡ”Ⓒ Dev Cloud Ninja Projects - Made with :yellow_heart: from DevCloud Ninjas
Source Files On GitHub
Section titled “Source Files On GitHub”The full learning flow stays on this page. Open GitHub only when a step asks you to inspect code, fork the lab, or download source assets.