diff --git a/.gitignore b/.gitignore index 0059dc7..d1c794f 100644 --- a/.gitignore +++ b/.gitignore @@ -37,3 +37,4 @@ override.tf.json # Ignore CLI configuration files .terraformrc terraform.rc +*.local.md diff --git a/main.tf b/main.tf index ccc473a..a665d81 100644 --- a/main.tf +++ b/main.tf @@ -394,6 +394,7 @@ module "comet_eks" { # EKS Auto Mode (mutually exclusive with Karpenter) enable_auto_mode = var.eks_enable_auto_mode + disable_auto_mode = var.eks_disable_auto_mode auto_mode_node_pools = var.eks_auto_mode_node_pools # Karpenter prerequisites diff --git a/modules/comet_eks/main.tf b/modules/comet_eks/main.tf index 9a85785..365a805 100644 --- a/modules/comet_eks/main.tf +++ b/modules/comet_eks/main.tf @@ -244,14 +244,15 @@ module "eks" { # EKS Auto Mode. When enabled, the control plane provisions nodes via the # built-in node pools and the upstream module auto-creates/wires the Auto Mode - # node IAM role (so node_role_arn is intentionally omitted). The block is - # always sent — enabled = false explicitly disables Auto Mode so a cluster that - # previously had it on can be turned back off (a bare null would omit the - # argument and leave the last-applied config in place). - compute_config = { - enabled = var.enable_auto_mode - node_pools = var.enable_auto_mode ? var.auto_mode_node_pools : [] - } + # node IAM role (so node_role_arn is intentionally omitted). + # + # null, not { enabled = false } — EKS rejects an explicit disable on a cluster + # that never had Auto Mode. To turn it off on one that does, see + # disable_auto_mode. + compute_config = var.enable_auto_mode ? { + enabled = !var.disable_auto_mode + node_pools = var.disable_auto_mode ? [] : var.auto_mode_node_pools + } : null # Bake the Karpenter discovery tag directly into the node SG so it is never # dropped when Terraform modifies the security group during subsequent applies. @@ -312,6 +313,10 @@ module "eks" { } : {}, { configuration_values = local.coredns_config + # OVERWRITE so the native add-on adopts objects the old eks_blueprints_addons + # Helm release owns, instead of failing on ConfigurationConflict. DND-1573. + resolve_conflicts_on_create = "OVERWRITE" + resolve_conflicts_on_update = "OVERWRITE" } ) } : {}, @@ -328,6 +333,10 @@ module "eks" { role_arn = aws_iam_role.external_dns[0].arn service_account = "external-dns" }] + # As cert-manager above. NOTE: resolve_conflicts does not cover Pod Identity + # associations — a pre-existing external-dns one must be deleted first. + resolve_conflicts_on_create = "OVERWRITE" + resolve_conflicts_on_update = "OVERWRITE" }, var.eks_external_dns_addon_version != null ? { addon_version = var.eks_external_dns_addon_version diff --git a/modules/comet_eks/variables.tf b/modules/comet_eks/variables.tf index a2c4e37..10b26d2 100644 --- a/modules/comet_eks/variables.tf +++ b/modules/comet_eks/variables.tf @@ -725,6 +725,18 @@ variable "enable_karpenter" { } } +variable "disable_auto_mode" { + description = <<-EOT + Send an explicit Auto Mode disable while keeping enable_auto_mode = true. One + apply, to turn Auto Mode off on a cluster that has it — the coexistence SG + rules and addon pinning stay in place while AWS drains the nodes. Setting + enable_auto_mode = false instead omits compute_config, which would strip those + rules while the nodes still run. Clear both once the nodes are gone. + EOT + type = bool + default = false +} + variable "enable_auto_mode" { description = <<-EOT Enable EKS Auto Mode. When true, the EKS control plane can provision nodes diff --git a/variables.tf b/variables.tf index 2e878ce..709c3a1 100644 --- a/variables.tf +++ b/variables.tf @@ -155,6 +155,12 @@ variable "eks_enable_auto_mode" { default = false } +variable "eks_disable_auto_mode" { + description = "Send an explicit Auto Mode disable while keeping eks_enable_auto_mode = true. One apply, to turn Auto Mode off on a cluster that has it. See disable_auto_mode in modules/comet_eks/variables.tf." + type = bool + default = false +} + variable "eks_auto_mode_node_pools" { description = "Built-in EKS Auto Mode node pools to enable when eks_enable_auto_mode = true. Common values: \"system\", \"general-purpose\". Custom NodePool/NodeClass CRDs are managed via GitOps (ArgoCD), not this module." type = list(string)