Project challenges / verified progress
Beacon: build the ground it stands on

The engineering notebook

Give Beacon a place

How does Terraform create compute and then talk to the cluster it created?

Loading statusStage 6 of 9

  • Workspace not ready
  • Agent not ready
Focus25:00
A small focus ritual

0 focus sessions completed. Every fourth session offers a longer break. Start each phase when you are ready.

Study time never unlocks verified lesson progress.

Loading...

Loading verified progress...

Loading GitHub account...
Phase 3 — Run and authenticate safely

Step 01 of 06

Learn the concept

A cluster is not useful when it exists only in the cloud console. Your tools need its endpoint, certificate and credentials. Terraform can create that cluster, but using the Kubernetes provider against a thing that does not exist yet is where the classic chicken-and-egg problem arrives.

WHERE CLUSTER APPLY WAITSminutesNetworksubnets and rulesControl planemanaged API startsEKS ~10mNodesinstances joinProvidersKube and Helm initneeds API
Managed Kubernetes spends most of its time becoming an API server. Terraform can request it quickly, but the next provider cannot use a kubeconfig until the control plane is reachable and the identity is authorized.
Step 01

The ideas this is made of

Managed clusters move work, not responsibility

A managed Kubernetes service runs the control plane for you. You still choose regions, versions, node sizes, IAM, networking and upgrade timing. EKS charges for the control plane even when no Pods are running. A cheaper learning path can use one small EC2 instance and install lightweight Kubernetes later, but the same infrastructure questions remain: where does it run, who can reach it, and what does it cost per hour?

Node pools are the bill made visible

A node pool says how many machines of which type should join the cluster. t3.small is cheap but has limited memory. m7i.large is comfortable and costs more. Autoscaling changes count, not the fact that each node is an instance with disk, network and sometimes load balancer charges. Capacity planning starts with a boring table of sizes and prices.

Kubeconfig is a credentialed map

A kubeconfig names a cluster endpoint, the certificate authority to trust, and the user or exec plugin used to authenticate. It is not just a URL. Terraform can output the facts needed to build one, or the cloud CLI can fetch it. Treat it as sensitive enough to protect; depending on auth style, it may grant direct cluster access.

Kubernetes providers need a live cluster

The Terraform Kubernetes and Helm providers must configure a client before they manage Kubernetes objects. If their host, certificate or token comes from a cluster resource that does not exist yet, planning can fail or produce an apply that must be run in stages. Many teams separate cluster creation from in-cluster workloads for this reason. It is not cowardice; it is graph reality.

Provider wiring after a cluster exists
provider "kubernetes" {
  host                   = aws_eks_cluster.beacon.endpoint
  cluster_ca_certificate = base64decode(aws_eks_cluster.beacon.certificate_authority[0].data)

  exec {
    api_version = "client.authentication.k8s.io/v1beta1"
    command     = "aws"
    args        = ["eks", "get-token", "--cluster-name", aws_eks_cluster.beacon.name]
  }
}

This provider can only work after EKS returns an endpoint and certificate authority, and after the AWS identity is allowed to authenticate to the cluster.

Managed Kubernetes or cheap VM

ChoiceGood atCost warning

EKS

Real managed cluster

Control plane about $0.10/hr

Single EC2

Cheap learning host

You operate Kubernetes

Local kind

Zero cloud cost

Not real cloud infra

Fargate

No node care

Pricing model changes

What these are called on the job

  • Control plane — The Kubernetes API server and controllers that manage cluster state.

  • Node pool — A managed group of worker machines with a size, count and update policy.

  • Kubeconfig — Client configuration that tells Kubernetes tools where the API server is and how to authenticate.

  • Helm provider — A Terraform provider that installs Helm charts into a Kubernetes cluster.