cluster.provision-eks ​
Provision an AWS EKS control plane and managed nodegroup, then register and verify Kubernetes access.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Dag |
| Library | App-clusters-aws |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Organization UUID that will own the Kubernetes CloudConnection. |
aws_connection_uuid | uuid | Yes | — | AWS CloudConnection UUID used for provider calls. |
cluster_name | string | Yes | — | EKS cluster name. |
region | string | Yes | — | AWS region. |
cluster_role_arn | string | Yes | — | IAM role ARN for the EKS control plane. |
subnet_ids | list | Yes | — | VPC subnet IDs for the EKS control plane. |
security_group_ids | list | No | — | Security group IDs for the EKS control plane. |
kubernetes_version | string | No | — | Requested Kubernetes version. |
endpoint_public_access | boolean | No | — | Whether the EKS public endpoint is enabled. |
endpoint_private_access | boolean | No | — | Whether the EKS private endpoint is enabled. |
public_access_cidrs | list | No | — | CIDR blocks allowed to reach the public endpoint. |
nodegroup_name | string | Yes | — | Managed nodegroup name. |
node_role_arn | string | Yes | — | IAM role ARN for worker nodes. |
kubeconfig_role_arn | string | No | — | IAM role ARN used by aws eks get-token in the generated kubeconfig. |
node_subnet_ids | list | No | — | Worker subnet IDs. Defaults to subnet_ids. |
scaling_config | json | No | — | EKS nodegroup scaling config. |
instance_types | list | No | — | EC2 instance types for the nodegroup. |
capacity_type | string | No | — | EKS nodegroup capacity type. |
disk_size_gib | integer | No | — | Worker node disk size in GiB. |
tags | json | No | — | Provider tags applied to supported AWS resources. |
register_connection_name | string | No | — | Name for the registered Kubernetes CloudConnection. |
cluster_timeout_seconds | integer | No | — | Timeout while waiting for the control plane. |
nodegroup_timeout_seconds | integer | No | — | Timeout while waiting for the nodegroup. |
verify_timeout_seconds | integer | No | — | Reserved for future verification timeout support. |
poll_interval_seconds | integer | No | — | Poll interval for provider waiters. |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Organization UUID that will own the Kubernetes CloudConnection. |
aws_connection_uuid | uuid | Yes | — | AWS CloudConnection UUID used for provider calls. |
cluster_name | string | Yes | — | EKS cluster name. |
region | string | Yes | — | AWS region. |
cluster_role_arn | string | Yes | — | IAM role ARN for the EKS control plane. |
subnet_ids | list | Yes | — | VPC subnet IDs for the EKS control plane. |
security_group_ids | list | No | — | Security group IDs for the EKS control plane. |
kubernetes_version | string | No | — | Requested Kubernetes version. |
endpoint_public_access | boolean | No | — | Whether the EKS public endpoint is enabled. |
endpoint_private_access | boolean | No | — | Whether the EKS private endpoint is enabled. |
public_access_cidrs | list | No | — | CIDR blocks allowed to reach the public endpoint. |
nodegroup_name | string | Yes | — | Managed nodegroup name. |
node_role_arn | string | Yes | — | IAM role ARN for worker nodes. |
kubeconfig_role_arn | string | No | — | IAM role ARN used by aws eks get-token in the generated kubeconfig. |
node_subnet_ids | list | No | — | Worker subnet IDs. Defaults to subnet_ids. |
scaling_config | json | No | — | EKS nodegroup scaling config. |
instance_types | list | No | — | EC2 instance types for the nodegroup. |
capacity_type | string | No | — | EKS nodegroup capacity type. |
disk_size_gib | integer | No | — | Worker node disk size in GiB. |
tags | json | No | — | Provider tags applied to supported AWS resources. |
register_connection_name | string | No | — | Name for the registered Kubernetes CloudConnection. |
cluster_timeout_seconds | integer | No | — | Timeout while waiting for the control plane. |
nodegroup_timeout_seconds | integer | No | — | Timeout while waiting for the nodegroup. |
verify_timeout_seconds | integer | No | — | Reserved for future verification timeout support. |
poll_interval_seconds | integer | No | — | Poll interval for provider waiters. |
describe_subnets | json | No | — | Output from aws.ec2.describe_subnets. |
create_cluster | json | No | — | Output from aws.eks.create_cluster. |
wait_cluster_active | json | No | — | Output from aws.eks.wait_cluster_active. |
create_nodegroup | json | No | — | Output from aws.eks.create_nodegroup. |
wait_nodegroup_active | json | No | — | Output from aws.eks.wait_nodegroup_active. |
build_kubeconfig | json | No | — | Output from aws.eks.build_kubeconfig. |
register_kubernetes_connection | json | No | — | Output from cluster.register-kubernetes-connection. |
verify_kubernetes_connection | json | No | — | Output from cluster.verify-kubernetes-connection. |
connection_uuid | uuid | No | — | Registered Kubernetes CloudConnection UUID. |
provider_cluster_ref | string | No | — | EKS cluster ARN or name. |
cluster_endpoint | string | No | — | Kubernetes API endpoint. |
status | string | No | — | Aggregated provision status. |
completed_at | string | No | — | ISO-8601 completion timestamp. |
workflow_run_uuid | string | No | — | Engine DAG run UUID for child step state. |
failure_reason | string | No | — | Engine failure reason. |
failed_step | json | No | — | Failed DAG step. |
failed_layer | json | No | — | Failed DAG layer. |
failed_at_state | json | No | — | Failed state metadata. |
error | string | No | — | Error message. |
error_type | string | No | — | Error class. |
compensation_trigger | json | No | — | DAG compensation trigger. |
comp_current_layer | json | No | — | Current compensation layer. |
comp_queue | json | No | — | Remaining compensation queue. |
comp_retry_count | json | No | — | Current compensation retry count. |
DAG Layers ​
| # | Layer | Steps | Compensation |
|---|---|---|---|
| 1 | validate_network | aws.ec2.describe_subnets | — |
| 2 | create_cluster | aws.eks.create_cluster | cluster.delete-eks |
| 3 | wait_cluster | aws.eks.wait_cluster_active | — |
| 4 | create_nodegroup | aws.eks.create_nodegroup | cluster.delete-eks |
| 5 | wait_nodegroup | aws.eks.wait_nodegroup_active | — |
| 6 | build_kubeconfig | aws.eks.build_kubeconfig | — |
| 7 | register_connection | cluster.register-kubernetes-connection | cluster.delete |
| 8 | verify_connection | cluster.verify-kubernetes-connection | — |
Execution Flow ​
Compensation ​
When any layer fails, its compensation steps run in reverse order to roll back the work completed so far.
Sub-workflows ​
| Sub-workflow | Step name |
|---|---|
aws.ec2.describe_subnets | describe_subnets |
aws.eks.create_cluster | create_cluster |
aws.eks.wait_cluster_active | wait_cluster_active |
aws.eks.create_nodegroup | create_nodegroup |
aws.eks.wait_nodegroup_active | wait_nodegroup_active |
aws.eks.build_kubeconfig | build_kubeconfig |
cluster.register-kubernetes-connection | register_kubernetes_connection |
cluster.verify-kubernetes-connection | verify_kubernetes_connection |
cluster.delete-eks | delete_eks_cluster |
cluster.delete | delete_registered_cluster |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "cluster.provision-eks",
"initial_data": {
"organization_uuid": "value",
"aws_connection_uuid": "value",
"cluster_name": "value",
"region": "value"
}
}