AWS Kubernetes Services (EKS) Deployment Example
This how-to guide is an example AWS Kubernetes deployment. This is not the only way to deploy a Kubernetes cluster.
Follow your organization’s security requirements for Kubernetes clusters.
Setup Summary
The following Azure resources are used in this example deployment.
- AWS CLI
- EKSCTL
- AWS S3 Bucket
Install AWS CLI
The AWS Command-Line Interface (CLI) allows you to interact with AWS resources from a terminal or command prompt.
Select your operating system to view installation instructions. Note: Instructions for Windows systems will be available soon.
macOS
Ubuntu
-
Install curl using Brew.
-
Install the AWS CLI.
-
Confirm the installation by checking the app version.
-
Configure AWS CLI
You must authenticate to your AWS account to access AWS resources using the AWS CLI.
This example uses the us-east-1 region. This is the default region for AI Supply Chain Security.
-
Configure the AWS CLI. (Note: This step has you manually entering your data. Using a configuration file may be more secure.)
-
Enter your:
a. AWS Access Key ID b. AWS Secret Access Key c. Default Region d. Default Output Format
Amazon S3
- The default bucket name for Supply Chain is hl-modelscan. To change the default bucket name, set the HL_MODEL_SCAN_BUCKET environment variable in the yaml file.
- This example uses the us-east-1 region. This is the default region for Supply Chain.
-
Create an S3 bucket for Supply Chain.
-
Create the IAM user. Save the output for later use.
-
Run the following command to write an IAM policy document to allow the Supply Chain to access the S3 bucket. Replace
<bucket>with the S3 bucket name you created earlier. This outputs a file namedhl-modelscanner-s3-policy.jsonto the current folder. -
Attach the IAM policy for the S3 bucket to the previously created user.
-
Generate Access Keys for the user.
-
Save the AccessKeyId and SecretAccessKey fields from the aws iam create-access-key response. They will be used later as the AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY when deploying the Supply Chain.
Install EKSCTL
EKSCTL is a command line tool that helps you create an EKS cluster, including the supporting resources for that cluster. It is used for this demonstration to help simplify the process.
Select your operating system to view installation instructions. Note: Instructions for Windows systems will be available soon.
macOS
Ubuntu
-
Install the Weaveworks Tap and Weaveworks EKSCTL.
Create EKS Cluster
-
Creating an EKS cluster using EKSCTL only requires one command. Replace
<cluster-name>with the name you want to give the cluster. Replace<aws-region>with the region you want to deploy the cluster in. Creating the cluster can take some time.
Connect Local Kubectl to EKS Cluster
-
Use the following command to connect your local kubectl instance to your AWS EKS cluster. Replace
<aws-region>and<cluster-name>with the information you used in the previous step.
Set Default Storage Class
A default storage class is needed for some of the Supply Chain pods, like the Redis pods. Setting a default storage class allows clusters to be created without needing to be assigned to the storage class.
When creating an EKS cluster using EKSCTL, a GP2 storage class is also created.
-
Get a list of the StorageClasses in the cluster.
-
Make the GP2 storage class the default. This allows pods to be automatically assigned to the storage resource.
Enable IAM OIDC Provider
To use AWS Identity and Access Management (IAM) roles for service accounts, an IAM OIDC provider must exist for your cluster’s OIDC issuer URL.
-
Create an IAM OIDC identity provider for your cluster with the following command. Replace
<aws-region>with the region you want to deploy the cluster in. Replace<cluster-name>with the name of the cluster.
Create AWS EBS CSI Driver IAM Role
The Amazon EBS CSI driver Amazon EKS add-on is a Kubernetes Container Storage Interface (CSI) plugin that provides Amazon EBS storage for your cluster.
-
Use the following command to create an IAM role and attach the managed policy to it. Replace
<aws-region>with the region you want to deploy the cluster in. Replace<cluster-name>with the name of the cluster.
Create AWS EBS CSI Addon
Create AWS EBS CSI add-ons to manage your EKS cluster.
-
Replace
<cluster-name>with the name of the cluster.