Launch a Kubernetes Cluster
Here's your beginner friendly intro to Kubernetes and AWS EKS!
Introduction
⚡️ 30 second summary
Welcome to this project on Kubernetes and Amazon EKS (Elastic Kubernetes Service)!
This project is part ONE of our four-part Kubernetes series, taking you from zero experience to deploying a containerized app 🚀
In this project, we'll deploy our first Kubernetes cluster, learning what it does and why people love it along the way.
In this project, get ready to...
- 🌠 Launch and connect to an EC2 instance.
- ✨ Create your very own Kubernetes cluster.
- ☁️ Monitor cluster creation with CloudFormation.
- 🔑 Access your cluster using an IAM access entry.
- 💎 (Secret Mission) Test the resilience of your Kubernetes cluster.
Want a complete demo of how to do this project, from start to finish? Check out our 🎬 walkthrough with Natasha 🎬
If you're up for a bit of a challenge, quiz yourself on the key concepts up ahead in this project.
This project is part of a series:
- Part 1: You are here!
- Part 2: Set Up Kubernetes Deployment
Before we start Step #1...
Before we get started, it's important that you know what we're trying to do today...
Launch and connect to an EC2 instance
Let's kick things off by setting up our very own EC2 instance, which we'll use to send commands to Kubernetes in this project series.
In this step, get ready to:
- Launch an EC2 instance.
- Connect to your instance so you can start sending commands.
Launch an EC2 Instance
- Log into your AWS Management Console as your IAM Admin user.
I don't have an IAM user!
If you don't have an IAM user, check out Step #5 in our intro project on containers. We'd also completing that project first to understand how containers work before diving into Kubernetes!
- Head to EC2 in your AWS Management Console.
- Select Instances at the left hand navigation bar.
- Check that you're using the AWS Region that's closest to you. Select the Region name at the top right corner of your console if you'd like to switch.
- Select Launch instances at the top right corner of your console.
- Name your EC2 instance nextwork-eks-instance
- For the Amazon Machine Image, select Amazon Linux 2023 AMI.
What is AMI? What is Free tier eligible?
An AMI (Amazon Machine Image) is a template or blueprint used to create EC2 instance. The image defines your EC2 instance's operating system and with the applications needed to launch the instance.
Free tier eligible AMIs are those that qualify for the AWS Free Tier, so you won't get charged for using it. Just remember that not all AMIs are free!
- For the Instance type, select t3.micro.
What is instance type?
If AMIs give you pre-built software and operating systems, instance types cover the 'hardware' components. CPU power, memory size, storage space and more!
So, while the AMI decides what operating system your server runs, the instance type determines how fast and powerful it performs.
For example, a larger instance type might have more CPU power for heavy tasks, while a smaller type (for example, t3.micro) might be more affordable for light use.
- For the Key pair (login) panel, select Proceed without a key pair (not recommended).
What is a key pair?
A key pair is like a lock and a key for your EC2 instance. Usually you'd need a key pair to SSH connect to your instance, but we're using a simpler way to do this later in this step (EC2 Instance Connect).
If you're new to key pairs and SSH connections and want to learn more, check out Steps #1 and #2 of Testing VPC Connectivity.
- We won't change anything in the Networking section and keep the default security group.
- Notice that the security group allows SSH traffic from anywhere (0.0.0.0/0) which isn't the best security practice, but we'll leave this to make connecting via SSH easier later on.
- We'll also leave the default storage settings, which gives your EC2 instance 8 GiB (i.e. about 8.5 GB) of storage space!
- Select Launch instance.
Connect to Your Instance
Now that our EC2 instance is up and running, let's connect to it using EC2 Instance Connect.
What is EC2 Instance Connect?
EC2 Instance Connect is a shortcut way to get direct SSH access to your EC2 instance. Instead of having to manage a key pair manually, Instance Connect connects you to your instance within your AWS Management Console - no download required!
💡 Extra for Experts: Why are we using EC2 Instance Connect?
To connect to an EC2 instance via SSH (which you can learn how to do in Set Up a Web App in the Cloud), you usually need to:
- Generate a key pair.
- Associate the public key with your EC2 instance.
- Securely store your private key on your local machine.
- Set up an SSH client (a software that can handle the SSH protocol, like Terminal on Max/Linux or VS Code).
- Provide your private key and run ssh commands to set up an SSH connection to your EC2 instance.
EC2 Instance Connect lets us skip all those steps and connect to your EC2 instances directly using the AWS Management Console. We'd use the usual, manual way when we have some development work to do, but Instance Connect is great if we're just running a few commands in the terminal.
- Select the instance you just launched.
- Select the Connect button.
- Welcome to the instance connection page! This is where AWS gives you different options to connect with your EC2 instance.
- Select Connect at the bottom of the page.
- This will open a terminal session directly in your browser in a new tab.
Launch an EKS cluster (and get an error)
Now for the main event – creating our Kubernetes cluster with Amazon EKS!
We'll use a handy command-line tool called eksctl to create a cluster within your EC2 instance's termninal.
What is Kubernetes?
Kubernetes is a tool that helps you manage your running containers.
Once you've created containers (e.g. using Docker), Kubernetes helps keep them running smoothly by automatically handling tasks like load balancing, scaling, and restarting containers if they fail. It doesn’t build the containers (that’s Docker’s job) but it’s great for keeping them running without you having to manage it manually.
💡 What is Amazon EKS?
While Kubernetes makes it easier to work with containers, Amazon EKS makes it easier to work with Kubernetes itself!
Setting up Kubernetes from scratch can be quite a time consuming and complex thing to do, because you'd need to configure Kubernetes' networking, scaling, and security settings on your own. Amazon EKS handles all of these set up tasks for you and helps you integrate Kubernetes with other AWS services.
eksctl is a tool specifically for working with EKS in the command line (more on this soon).
In this step, get ready to:
- Attempt to create an EKS cluster (and run into an error)!
- Install a tool for creating Kubernetes clusters called eksctl.
Let's try creating a cluster right away.
- In your EC2 Instance Connect window, run this command:
eksctl create cluster \
--name nextwork-eks-cluster \
--nodegroup-name nextwork-nodegroup \
--node-type t3.micro \
--nodes 3 \
--nodes-min 1 \
--nodes-max 3 \
--version 1.33
What does this command do?
This command is meant to set up a Kubernetes cluster! We'll dive into the specifics of this command and Kubernetes in just a second. For now...
... you'll likely see an error message saying something like eksctl not found.
Don't worry, this is expected! It means we haven't installed eksctl yet.
What is eksctl?
eksctl is an official AWS tool for managing Amazon EKS clusters in your terminal. It's much, much easier to use compared to setting up a Kubernetes cluster using the AWS CLI!
If we were using the AWS CLI, we'd have to create a lot of other components manually before getting to deploy a cluster. You'll learn what these components are in Step #4.
Install eksctl
- Run these commands in your terminal:
curl --silent --location "https://github.com/weaveworks/eksctl/releases/latest/download/eksctl_$(uname -s)_amd64.tar.gz" | tar xz -C /tmp
sudo mv -v /tmp/eksctl /usr/local/bin
What do these commands do?
The commands download and install eksctl on your EC2 instance.
The first commands downloads the latest eksctl release from GitHub, then the second command moves it to a directory within your EC2 instance that lets you run eksctl from anywhere in your terminal.
- Check that eksctl is installed correctly by running eksctl version. You should see the version number printed in the terminal.
I don't see a version number!
No stress! Try refreshing the Instance Connect tab and run the installation commands again.
Does a version number pop up the second time?
If you're still stuck, ask the NextWork community!
Launch an EKS cluster (for real this time)
Now that eksctl is all installed, let's give launching an Kubernetes cluster on EKS another go. We'll also learn about giving your EC2 instance the permission to run AWS commands!
Note
Creating a Kubernetes cluster and using EKS is not AWS Free Tier eligible, so expect to spend $0.10 USD for every hour you leave your EKS cluster running once it's created.
Make sure to follow all the deletion instructions at the end of this project to minimise costs for this project.
In this step, get ready to:
- Attempt to create an EKS cluster (and run into an error again)!
- Set up your EC2 instance's IAM role.
- Create an EKS cluster using eksctl.
Now that eksctl is installed, let's try creating our cluster again.
- Run this command:
eksctl create cluster \
--name nextwork-eks-cluster \
--nodegroup-name nextwork-nodegroup \
--node-type t3.micro \
--nodes 3 \
--nodes-min 1 \
--nodes-max 3 \
--version 1.33 \
--region [[AWS_REGION="your-region-code"]]
- Don't forget to replace your-region-code in the last line of the command with your AWS region code, e.g. us-west-2. Make sure the region you pick is same region where you launched your EC2 instance.
Dang it! What's the error this time?
Your EC2 instance doesn’t have the permission to create an EKS cluster yet. By default, imagine every EC2 instance you launch as a brand new computer that hasn’t signed in to your AWS account. We’ll need to set up an IAM role that lets your EC2 instance communicate with services like EKS to create the cluster.
Create an IAM role for your EC2 instance
Let's resolve this permissions error by setting up a new Role in AWS IAM.
- In a new tab, head to your AWS IAM console.
- Select Roles from the left hand sidebar.
- Select Create role.
- Under Trusted entity type, select AWS service to tell AWS that we're setting up this role for a AWS serice (Amazon EC2).
- Under Use case, select EC2.
- Select Next.
- Under Permissions policies, we'll grant our EC2 instance AdministratorAccess.
What does this permission policy mean?
AdministratorAccess gives your EC2 instance the permission to access any AWS resource and service in your AWS account.
A super powerful move, which your EC2 instance will need when it deploys and manages your Kubernetes cluster (your instance will be using a lot of different services).
💡 Extra for Experts: Is granting AdministratorAccess best practice?
Great question! Granting AdministratorAccess is powerful but not ideal for long-term use. We’re using it now because we don’t know all the services that will be involved in the project yet.
Granting the most powerful permissions now means we avoid running into permission issues that could slow us down. Once we know which services your EC2 instance really needs for this project to work, we can dial back to more specific, secure settings.
Solution Architects typically plan security settings before they build anything, aiming to follow the principle of least privilege (only giving the exact permissions needed for the job).
- Make sure the AdministratorAccess option is checked, and select Next.
- Let's give this role a straightforward name - nextwork-eks-instance-role
- Enter a short description:
Grants an EC2 instance AdministratorAccess to my AWS account. Created during NextWork's Kubernetes project.
- Select Create role.
Attach IAM role to EC2 instance
Great! Your new role is born. Now we'll add this role to our EC2 instance.
- Head back to the EC2 console.
- Select Instances from the left hand sidebar.
- Select the checkbox next to your nextwork-eks-instance EC2 instance.
- Select the Actions dropdown, and then Security -> Modify IAM role.
- Under IAM role, select your new nextwork-eks-instance-role role.
- Select Update IAM role.
Create your EKS cluster agains (third time lucky)!
- Still in your browser, head back to your EC2 Instance Connect tab.
- Let's run the command to kick off our Kubernetes cluster one more time...
eksctl create cluster \
--name nextwork-eks-cluster \
--nodegroup-name nextwork-nodegroup \
--node-type t3.micro \
--nodes 3 \
--nodes-min 1 \
--nodes-max 3 \
--version 1.33 \
--region [[AWS_REGION="your-region-code"]]
What does this command do?
We'll learn all these terms over the rest of this project, but as a sneak peek, this command will:
- Set up an EKS cluster named nextwork-eks-cluster
- Launch a node group called nextwork-nodegroup.
- Use t3.micro EC2 instances as nodes.
- Start your node group with 3 nodes and automatically scale between 1 (minimum) and 3 nodes (maximum) based on demand.
- Use Kubernetes version 1.31 for the cluster setup.
⏰ Check the time on your computer now. Don't forget that EKS charges $0.10 for every hour your cluster is running.
Creating a cluster can take 15-20 minutes, so grab a drink and read on to know more about Kubernetes while we wait.
What is Kubernetes?
Kubernetes is a container orchestration platform, which is a fancy way to say that it coordinates containers so they're running smoothly across all your servers. It makes sure all your containers are running where they should, scales containers automatically to meet demand levels, and even restarts containers if something crashes.
It’s THE standard tool for keeping large, container-based applications steady and easy to scale with traffic. That's why big tech companies, startups, and developers worldwide use Kubernetes.
💡 Why do people use Kubernetes?
Without a tool like Kubernetes, you would create and manage every container manually. You’d have to start each container yourself and keep an eye on them to restart any that crash.
Traffic to your app going up or down would mean turning containers on or off one by one, and you’d also have to make sure each container has access to storage if it needs it. Updating your app would mean carefully swapping out containers without causing downtime.
As you might imagine, managing hundreds or thousands of containers this way would be a huge amount of work and hard to get right all the time. Kubernetes takes care of all these tasks automatically, so you can focus on building your app's features instead.
Still waiting on your terminal to finish running the command? Head to the next step anyway, you don't need your cluster to be ready to do it!
Track how AWS creates your EKS cluster
Let's take a tour around the AWS Management Console to see how AWS actually creates a Kubernetes cluster. What happens under the hood when you ran eksctl create cluster?
In this step, get ready to:
- Use CloudFormation to track how your cluster is getting created.
- In a new tab, head to the CloudFormation console.
What is CloudFormation?
CloudFormation is AWS’s service for setting up infrastructure as code. You write a template describing the resources you need (like an instruction manual), and CloudFormation handles creating and configuring those resources.
💡 Why are we in CloudFormation?
eksctl actually uses CloudFormation under the hood to create your EKS cluster.
When you ran the eksctl create cluster command, eksctl sets up a CloudFormation stack to automate the creation of all the necessary resources for the EKS cluster.
- In the Stacks page, notice that there is a new stack in progress! The stack should be called eksctl-nextwork-eks-cluster-cluster.
- Select the stack, and track the Events tab.
- Woah, turns out there are heaps of events happening in the background... cool!
What are these Events about?
The Events tab gives you a timeline of each action CloudFormation is taking to set up your resources. It’s a live update of what’s happening, which can be helpful for tracking progress or identifying any issues that come up during creation.
You can even select the Refresh button at the top of the panel to watch new updates come through on your stack's resources.
- Now select the Resources tab.
- Lots of resources are getting created here!
What are these resources?
You might notice in your Resources tab all sorts of networking resources - VPC, subnets, route tables, security groups, NAT gateways and internet gateways!
These resources set up a private, secure network for your containers to connect with each other and the internet while keeping your app private. It's not required for this project that you understand all these components, but you can learn more about VPC resources at Launching VPC Resources.
Note that this is one of the big reasons why you'd pick eksctl over the AWS CLI - if we were using AWS CLI, we'd have to create each of these resources manually!
💡 Extra for Experts: Why can't I just use my account's default VPC?
While you could use your AWS account's default VPC, you might need to manually set up new VPC resources and edit a few settings to make it work for a Kubernetes cluster. eksctl creates a whole new VPC for us to let us start fresh.
- You might also notice a NEW stack pop up in the Stacks page. This should pop up 10-12 minutes from the time you ran the create cluster command.
Why is there a second stack?
The second stack is specifically for your node group, which is a group of EC2 instances that will run your containers.
CloudFormation separates the core EKS cluster stack from the node group stack to make it easier to manage and troubleshoot each part independently, especially if one half fails.
💡 What's the difference between a cluster and a node group?
Think of a cluster as the entire environment that Kubernetes manages for your containerized app. This cluster is made up of nodes (the servers that actually run your containers) and a control plane (the brain that decides things like when to create or shut down containers).
Within your cluster, the nodes are organized into node groups. Node groups let you manage multiple nodes more easily by grouping them together, so you can control settings like instance type and resource limits for the whole group instead of adjusting each node individually. This makes it much simpler to scale and configure nodes for specific tasks.
- Select the nodegroup stack, and open up the Events tab to get a preview of what being deployed.
- Wait until the first stack i.e. eksctl-nextwork-eks-cluster-cluster is in CREATE_COMPLETE status.
If your second stack isn't complete yet, that's okay - we can still head to the next step in the meantime!
Extra for Experts: Why is there a red line in my terminal output?
OOo! Some of our eagled-eye learners have pointed out that even if their cluster creation is successful, they noticed there is a single red line in their Instance Connect terminal...
The error says [✖] kubectl not found, v1.10.0 or newer is required
Think of this intriguing red line as a warning that while eksctl has successfully set up your cluster, you’ll need kubectl to interact with it. It won't actually stop you from creating the cluster!
You’ll learn more about kubectl in Project 4 of the Kubernetes series, but in short it's a tool you’d use to create Kubernetes resources. Without Kubernetes resources, you won’t get to deploy your application to your cluster.
Access EKS from the Management Console
Now that our EKS cluster is ready, let's see it using the AWS Management Console.
In this step, get ready to:
- Open the EKS console.
- Grant yourself the permissions to interact with your cluster.
Accessing the EKS Console
- In a new tab, open up the EKS console.
- Select the new nextwork-eks-cluster cluster you just created.
- Welcome to your EKS cluster's dedicated page!
- Select the Compute tab.
- Scroll down to the Node groups panel - aha, it's getting created!
- If it's been some time since you ran your create cluster command, you might even notice that it's already in Created status.
- Refresh your cluster's page. Notice that there is a banner in blue...
What is this blue banner saying?
The blue banner is telling you that while you've created a node group, you might not have the permission to see the nodes inside!
💡 But my IAM User has AdministratorAccess - how could it not have permission?
AWS permissions alone don’t automatically carry over to Kubernetes - Kubernetes has its own way of managing access within a cluster.
Even if you have AdministratorAccess in AWS, which grants full access to AWS resources, Kubernetes will only let you into different parts of the cluster if you have permissions under its own system too.
Let's learn about this system and grant ourselves access now!
Set up your own access to your cluster
- Select Create access entry at the blue banner at the top of the page.
I don't see that top banner
No problemo! There's a second way to get to the same place:
- Head to the Access tab
- Under IAM access entries, select Create access entry.
💡 What are IAM access entries?
An IAM access entry is like a handshake that connects AWS and Kubernetes. IAM is AWS’s login and permission system, while RBAC (Role Based Access Control) is Kubernetes’s. The entry maps your IAM role to an RBAC role, so the cluster lets you access your nodes.
Nice work, we can now set up an IAM access entry.
- Under IAM Principal, select your IAM user's ARN. Double check your IAM Admin's name at the top right corner and make sure it matches your ARN.
- Let's keep the Type as Standard.
What are the different Types?
The Type field is EKS asking you “are we giving access to a person or a machine?”
Pick Standard when you’re adding a human, script, or external service so you can fine-tune access later with EKS policies or Kubernetes RBAC.
All of the other Type values are for machines, not people e.g. EC2 Linux. Once EKS understands the Type, it can auto-grant the minimal rights the person/machine should need.
- Select Next.
- Under Policy name, select AmazonEKSClusterAdminPolicy.
What does this policy do?
The AmazonEKSClusterAdminPolicy gives you full administrative rights over your EKS clusters. Your IAM user will be able to see and control all parts of your EKS cluster - inclusding all the nodes inside!
- Leave Access scope as is.
What does access scope mean?
Access scope tells AWS how much of your Kubernetes cluster a person or application can touch.
- Choose Cluster if you want them to have a master key that can access everything in your cluster.
- Pick Kubernetes namespace if you’d rather limit access to a single namespace, which is a labelled section inside your cluster. This keeps accidental changes or security issues contained to that one area while the rest of the cluster stays untouched.
- Select Add policy.
- Select Next.
- In the review page, let's confirm...
- The IAM principal ARN is your IAM Admin user.
- The Policy name is AmazonEKSClusterAdminPolicy.
- Select Create.
- Woohoo! Once the access policy is created, let's head back to your cluster's page.
- Select the refresh button on the console. You should now see your nodes listed under your node group.
Why are there three nodes but one node group?
The node group is a group of nodes that share the same settings, like instance type and scaling. In this case, our node group has three nodes, which means there are three EC2 instances that will run containers like a single unit.
I don't see any nodes
Totally possible!
- Head back to your CloudFormation console.
- Is your nodegroup stack in CREATE_COMPLETE too? If not, wait a few more moments.
- Is your nodegroup cluster showing ROLLBACK_COMPLETE? Select the Events tab for that Stack and select Detect root cause to check why it's failed. See if you can resolve the root cause on your own, or share a screenshot of the root cause with the NextWork community if you're stuck!
- Everything looks okay in CloudFormation? Refresh your EKS console again just in case, or ask the NextWork community!
Nice work creating your very first Kubernetes cluster with Amazon EKS!
Well done on setting up the basics of Amazon EKS. You'll go through this process of creating an EKS cluster again in the next project of this Kubernetes series.
Secret mission
Welcome to your 🤫 exclusive 🤫 secret mission.
Your mission, should you choose to take it, is to test the resilience of your Kubernetes cluster. We'll delete some nodes and see how Kubernetes automatically recovers them like magic.
💎 In this secret mission, you're going to:
- Terminate EC2 instances in your Kubernetes cluster.
- Watch Kubernetes automatically replace the terminated instances.
- Showcase your secret mission in your project documentation.
Delete nodes (and watch them regenerate)
Delete Your Resources
Delete Your Resources
Important
Deleting resources that are not actively being used stops you getting charged and is a best practice. Not deleting your resources will result in charges to your account.
Do you have time for another project today?
Yep, let's go!
Nice, you don't need to delete your resources just yet!
Once you're done checking out your documentation for this project, you can head straight to the next project in this series.
Nope, not today.
Alrighty, we'll need to delete all the resources we've spun up today to avoid any surprise charges.
Challenge yourself to delete everything in this project on your own before you follow the instructions!
✋ STOP - INSUTRUCTIONS BELOW
- Delete EKS Cluster
The easiest way to delete your entire EKS cluster is by deleting the CloudFormation stacks.
- Head to the CloudFormation console.
- Select the first stack on the list (eksctl-nextwork-eks-cluster-nodegroup-nextwork-nodegroup).
- Select Delete.
- Select Delete again.
- The status for that stack should turn into DELETE_IN_PROGRESS.
- Select the second stack on the list(eksctl-nextwork-eks-cluster-cluster).
- Select Delete, and Delete again.
- This process can take up to 10 minutes, we'll come back to double check we've deleted everything later!
- Terminate EC2 Instance
- Head to the EC2 console.
- Select the checkbox next to nextwork-eks-instance.
- Select Instance state
- Select Terminate (delete) instance.
- Select Terminate (delete)
- Check your CloudFormation deletion
- Head to the CloudFormation console.
- Double-check that your two stacks say DELETE_COMPLETE.
- Make sure it says DELETE_COMPLETE before you finish up for the day! EKS is not Free Tier eligible, so you'll get charged for every hour your cluster is left running.
Please check
Please also check for an Elastic IP address in the EC2 console - some students have been charged for keeping it! If you find one, release the Elastic IP so it's no longer in your account.
Nice Work!
Nice Work!
You've just launched your first Kubernetes cluster on AWS!
You've learned how to:
- 🌠 Launch and connect to an EC2 instance.
- 🛠️ Install and use eksctl to create an EKS cluster.
- ☁️ Track cluster creation using CloudFormation.
- 🔑 Manage IAM access policies.
- 💎 (Secret Mission) Test the resilience of your cluster by terminating nodes.
Give yourself a pat on the back – that's no small feat. Are you ready to quiz yourself? 💪
Well done on making start as a Kubernetes pro. See you in the next part of this series - Set Up Kubernetes Deployment - where your cluster will start running container images and have a load balancer handling traffic!
p.s. Does it say "Still tasks to complete!" at the bottom of the screen?
This means you still have screenshots left to upload, or questions left to answer!
- Press Ctrl+F (Windows) or Command+F (Mac) on your keyboard.
- Search for the text Return to later.
- Jump straight to your incomplete tasks!
- 🙋♀️ Still stuck? Ask the community!