Repository navigation
feat(eks): drop kubernetes provider — module is Kubernetes-API-free (v5.0.0 Chunk D) - #55
Merged
obezpalko merged 2 commits intoJul 31, 2026
Conversation
…v5.0.0) With every kubernetes_* resource gone (Chunk C), the kubernetes provider was declared-but-unused. Remove it from required_providers (root + comet_eks) and delete the exec-auth provider "kubernetes" config block in providers.tf (the chicken-and-egg source: it wired the provider to the not-yet-reachable cluster endpoint). Also delete time_sleep.wait_for_cluster_access — the last time_sleep, now with zero dependents. Result: terraform providers lists only aws / tls / time / random (+ cloudinit / null, transitive node-bootstrap deps of terraform-aws-modules/eks). No kubernetes/helm/kubectl anywhere. A step-1 apply on a private-endpoint EKS cluster the runner cannot yet reach now makes ZERO Kubernetes API-server connections; all in-cluster state is owned by ArgoCD (comet-infra) + ESO + the agentro RBAC module. terraform init + validate pass. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
obezpalko
merged commit Jul 31, 2026
79b13ec
into
feat/v5-chunk-c-relocate-k8s-resources
5 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
User description
Chunk D — the payoff. Stacked on #54. With all
kubernetes_*resources removed (Chunk C), the kubernetes provider was declared-but-unused. This removes it fromrequired_providers(root + comet_eks), deletes the exec-authprovider "kubernetes"block inproviders.tf(the chicken-and-egg source — it bound the provider to the not-yet-reachable cluster endpoint), and dropstime_sleep.wait_for_cluster_access(last time_sleep, zero dependents).Goal achieved: a step-1
terraform applyon a private-endpoint EKS cluster the runner cannot yet reach makes zero Kubernetes API-server connections. In-cluster state is owned by ArgoCD (comet-infra) + ESO + the agentro-role/rbac module.init+validatepass.Next: Chunk E — strip removed-var pass-throughs from the wrappers, tag v5.0.0, per-cluster non-destructive cutover (
state rmadopted objects → bump?ref), stsaasuat first.🤖 Generated with Claude Code
Generated description
Below is a concise technical summary of the changes proposed in this PR:
Remove the
kubernetesprovider and thetime_sleep.wait_for_cluster_accessdelay from the root andcomet_eksTerraform configuration so the EKS bootstrap path no longer connects to the cluster API during the first apply. Update the example variables and setup docs to match the simplified inputs and the renamed RDS password variable.kubernetesprovider and cluster-access wait from the root andcomet_eksEKS bootstrap path.Modified files (4)
Latest Contributors(2)
Modified files (2)
Latest Contributors(2)