aws module with the env zero provider and the Helm provider.
The configuration creates:
- A VPC, an EKS cluster with a managed node group, and the cluster autoscaler
- An agent pool and an agent secret in env zero
- The
env0-agentHelm release, configured with env zero hosted encrypted state, so the cluster needs no persistent volume
Prerequisites
- Terraform 1.3.2 or later, or OpenTofu
- AWS credentials that can create a VPC, an EKS cluster, IAM roles, and Auto Scaling group settings
- AWS CLI v2 and
bashon the machine that runs Terraform or OpenTofu. The Helm provider authenticates withaws eks get-token, and theawsmodule runsaws autoscalingcommands. - The Helm CLI, to run the chart tests in Verify the installation
- An env zero API key, exported as environment variables:
Create the configuration
Save the configuration below asmain.tf in an empty directory.
The example pins the module to v1.2.0. Check the k8s-modules releases and use the latest tag.
main.tf
aws module accepts more inputs, such as kubernetes_version, instance_types, and max_capacity. See the aws module reference.
Apply the configuration
-
Initialize the working directory:
-
Apply the configuration:
tofu init and tofu apply.
Verify the installation
-
Configure
kubectlfor the new cluster. If you changedcluster_nameorregion, use your values: -
Run the chart tests:
-
In env zero, go to Organization Settings > Agents. The agent pool named after
cluster_name(env0-agentby default) shows Active.
Assign the agent to a project
Add anenv0_agent_project_assignment resource to run a project’s deployments on the new agent:
main.tf
Use an existing EKS cluster
To install the agent on an EKS cluster that already exists, read the cluster with a data source instead of creating it:-
Remove the
module "cluster"block, and thedepends_online fromhelm_release. -
Add the
awsprovider torequired_providers:main.tf -
Replace the
provider "helm"block with:main.tf -
Set the
cluster_namevariable default to the name of your cluster.
env0-state-sc StorageClass.
Keep the state in your AWS account
If the deployment state and working directory must stay in your AWS account, store them on EFS instead of env zero hosted encrypted state. Make this choice before the first deployment runs on the agent.- In
module "cluster", removecreate_efs_storage = false. The module then creates an EFS file system, the EFS CSI driver, and theenv0-state-scStorageClass. - Remove the
random_passwordresource and theenv0StateEncryptionKeyblock fromhelm_release. Without the key, the agent chart creates a persistent volume claim onenv0-state-sc.
Next steps
- Custom/optional configuration - Add Helm values to
helm_release.env0_agent. - Authenticating the agent on AWS EKS - Give deployments an IAM role. The
oidc_provider_arnmodule output feeds the IAM role trust policy. - Hosting deployment logs - Store deployment logs in your AWS account.