Skip to content

feat(eks): drop kubernetes provider — module is Kubernetes-API-free (v5.0.0 Chunk D) - #55

Merged
obezpalko merged 2 commits into
feat/v5-chunk-c-relocate-k8s-resourcesfrom
feat/v5-chunk-d-drop-kubernetes-provider
Jul 31, 2026
Merged

obezpalko merged 2 commits into
feat/v5-chunk-c-relocate-k8s-resourcesfrom
feat/v5-chunk-d-drop-kubernetes-provider

Conversation

@obezpalko

@obezpalko obezpalko commented Jul 31, 2026 •

Copy link
Copy Markdown

User description

Chunk D — the payoff. Stacked on #54. With all kubernetes_* resources removed (Chunk C), the kubernetes provider was declared-but-unused. This removes it from required_providers (root + comet_eks), deletes the exec-auth provider "kubernetes" block in providers.tf (the chicken-and-egg source — it bound the provider to the not-yet-reachable cluster endpoint), and drops time_sleep.wait_for_cluster_access (last time_sleep, zero dependents).

terraform providers  →  aws · tls · time · random  (+ cloudinit · null, transitive eks node-bootstrap deps)
                        NO kubernetes / helm / kubectl

Goal achieved: a step-1 terraform apply on a private-endpoint EKS cluster the runner cannot yet reach makes zero Kubernetes API-server connections. In-cluster state is owned by ArgoCD (comet-infra) + ESO + the agentro-role/rbac module. init+validate pass.

Next: Chunk E — strip removed-var pass-throughs from the wrappers, tag v5.0.0, per-cluster non-destructive cutover (state rm adopted objects → bump ?ref), stsaasuat first.

🤖 Generated with Claude Code


Generated description

Below is a concise technical summary of the changes proposed in this PR:
Remove the kubernetes provider and the time_sleep.wait_for_cluster_access delay from the root and comet_eks Terraform configuration so the EKS bootstrap path no longer connects to the cluster API during the first apply. Update the example variables and setup docs to match the simplified inputs and the renamed RDS password variable.

TopicDetails
EKS bootstrap Remove the kubernetes provider and cluster-access wait from the root and comet_eks EKS bootstrap path.
Modified files (4)
  • modules/comet_eks/main.tf
  • modules/comet_eks/versions.tf
  • providers.tf
  • versions.tf
Latest Contributors(2)
UserCommitDate
alexb@comet.comfeat(eks): drop kubern...July 31, 2026
CRThazeMerge pull request #52...July 29, 2026
Docs cleanup Update the setup docs and example tfvars to match the new inputs and variable names.
Modified files (2)
  • README.md
  • terraform.tfvars.example
Latest Contributors(2)
UserCommitDate
alexb@comet.comremove terraform.tfvarsJuly 31, 2026
diegoc@comet.comExpose rds master user...August 08, 2025
Review this PR on Baz | Customize your next review

…v5.0.0)

With every kubernetes_* resource gone (Chunk C), the kubernetes provider was
declared-but-unused. Remove it from required_providers (root + comet_eks) and
delete the exec-auth provider "kubernetes" config block in providers.tf (the
chicken-and-egg source: it wired the provider to the not-yet-reachable cluster
endpoint). Also delete time_sleep.wait_for_cluster_access — the last time_sleep,
now with zero dependents.

Result: terraform providers lists only aws / tls / time / random (+ cloudinit /
null, transitive node-bootstrap deps of terraform-aws-modules/eks). No
kubernetes/helm/kubectl anywhere. A step-1 apply on a private-endpoint EKS cluster
the runner cannot yet reach now makes ZERO Kubernetes API-server connections;
all in-cluster state is owned by ArgoCD (comet-infra) + ESO + the agentro RBAC
module. terraform init + validate pass.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@obezpalko
obezpalko merged commit 79b13ec into feat/v5-chunk-c-relocate-k8s-resources Jul 31, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant