Step 01 of 06
Learn the concept
A cluster is not useful when it exists only in the cloud console. Your tools need its endpoint, certificate and credentials. Terraform can create that cluster, but using the Kubernetes provider against a thing that does not exist yet is where the classic chicken-and-egg problem arrives.
The ideas this is made of
Managed clusters move work, not responsibility
A managed Kubernetes service runs the control plane for you. You still choose regions, versions, node sizes, IAM, networking and upgrade timing. EKS charges for the control plane even when no Pods are running. A cheaper learning path can use one small EC2 instance and install lightweight Kubernetes later, but the same infrastructure questions remain: where does it run, who can reach it, and what does it cost per hour?
Node pools are the bill made visible
A node pool says how many machines of which type should join the cluster. t3.small is cheap but has limited memory. m7i.large is comfortable and costs more. Autoscaling changes count, not the fact that each node is an instance with disk, network and sometimes load balancer charges. Capacity planning starts with a boring table of sizes and prices.
Kubeconfig is a credentialed map
A kubeconfig names a cluster endpoint, the certificate authority to trust, and the user or exec plugin used to authenticate. It is not just a URL. Terraform can output the facts needed to build one, or the cloud CLI can fetch it. Treat it as sensitive enough to protect; depending on auth style, it may grant direct cluster access.
Kubernetes providers need a live cluster
The Terraform Kubernetes and Helm providers must configure a client before they manage Kubernetes objects. If their host, certificate or token comes from a cluster resource that does not exist yet, planning can fail or produce an apply that must be run in stages. Many teams separate cluster creation from in-cluster workloads for this reason. It is not cowardice; it is graph reality.
provider "kubernetes" {
host = aws_eks_cluster.beacon.endpoint
cluster_ca_certificate = base64decode(aws_eks_cluster.beacon.certificate_authority[0].data)
exec {
api_version = "client.authentication.k8s.io/v1beta1"
command = "aws"
args = ["eks", "get-token", "--cluster-name", aws_eks_cluster.beacon.name]
}
}
This provider can only work after EKS returns an endpoint and certificate authority, and after the AWS identity is allowed to authenticate to the cluster.
Managed Kubernetes or cheap VM
| Choice | Good at | Cost warning |
|---|---|---|
EKS | Real managed cluster | Control plane about $0.10/hr |
Single EC2 | Cheap learning host | You operate Kubernetes |
Local kind | Zero cloud cost | Not real cloud infra |
Fargate | No node care | Pricing model changes |
What these are called on the job
Control plane — The Kubernetes API server and controllers that manage cluster state.
Node pool — A managed group of worker machines with a size, count and update policy.
Kubeconfig — Client configuration that tells Kubernetes tools where the API server is and how to authenticate.
Helm provider — A Terraform provider that installs Helm charts into a Kubernetes cluster.
