Skip to main content
Use one Terraform or OpenTofu configuration to create an AWS EKS cluster and install the env zero self-hosted Kubernetes agent on it. The configuration combines the k8s-modules aws module with the env zero provider and the Helm provider. The configuration creates:
  • A VPC, an EKS cluster with a managed node group, and the cluster autoscaler
  • An agent pool and an agent secret in env zero
  • The env0-agent Helm release, configured with env zero hosted encrypted state, so the cluster needs no persistent volume
To install the agent on an EKS cluster you already have, see Use an existing EKS cluster.

Prerequisites

Creating agent pools and agent secrets requires an API key with the Edit Organization Settings permission. Self-hosted agents are available to Enterprise customers only.
  • Terraform 1.3.2 or later, or OpenTofu
  • AWS credentials that can create a VPC, an EKS cluster, IAM roles, and Auto Scaling group settings
  • AWS CLI v2 and bash on the machine that runs Terraform or OpenTofu. The Helm provider authenticates with aws eks get-token, and the aws module runs aws autoscaling commands.
  • The Helm CLI, to run the chart tests in Verify the installation
  • An env zero API key, exported as environment variables:

Create the configuration

Save the configuration below as main.tf in an empty directory. The example pins the module to v1.2.0. Check the k8s-modules releases and use the latest tag.
main.tf
Pass secret Helm values, such as agentAccessToken, env0StateEncryptionKey, or cloud credentials, with set_sensitive. Do not put them in values: the Helm provider stores values unredacted in the helm_release metadata, and terraform plan prints that metadata when the release changes.The state stores the agent secret and the state encryption key. Use an encrypted remote backend for this configuration. If the encryption key changes, existing environments that use local state lose their state. See Key rotation.
The aws module accepts more inputs, such as kubernetes_version, instance_types, and max_capacity. See the aws module reference.

Apply the configuration

  1. Initialize the working directory:
  2. Apply the configuration:
For OpenTofu, run tofu init and tofu apply.

Verify the installation

  1. Configure kubectl for the new cluster. If you changed cluster_name or region, use your values:
  2. Run the chart tests:
  3. In env zero, go to Organization Settings > Agents. The agent pool named after cluster_name (env0-agent by default) shows Active.

Assign the agent to a project

Add an env0_agent_project_assignment resource to run a project’s deployments on the new agent:
main.tf
Projects without an assignment use the organization default agent. See Running multiple self-hosted agents.

Use an existing EKS cluster

To install the agent on an EKS cluster that already exists, read the cluster with a data source instead of creating it:
  1. Remove the module "cluster" block, and the depends_on line from helm_release.
  2. Add the aws provider to required_providers:
    main.tf
  3. Replace the provider "helm" block with:
    main.tf
  4. Set the cluster_name variable default to the name of your cluster.
The cluster must meet the Self-Hosted Kubernetes Agent requirements. With env zero hosted encrypted state, the cluster needs no env0-state-sc StorageClass.

Keep the state in your AWS account

If the deployment state and working directory must stay in your AWS account, store them on EFS instead of env zero hosted encrypted state. Make this choice before the first deployment runs on the agent.
On an agent that already ran deployments, removing env0StateEncryptionKey loses the local state of existing environments, and Terraform re-creates their resources. Move those environments to a remote backend first. See Key rotation.
  1. In module "cluster", remove create_efs_storage = false. The module then creates an EFS file system, the EFS CSI driver, and the env0-state-sc StorageClass.
  2. Remove the random_password resource and the env0StateEncryptionKey block from helm_release. Without the key, the agent chart creates a persistent volume claim on env0-state-sc.

Next steps