{"id":16409630,"url":"https://github.com/eddycharly/terraform-provider-kops","last_synced_at":"2026-03-11T01:31:02.269Z","repository":{"id":37013203,"uuid":"309453419","full_name":"eddycharly/terraform-provider-kops","owner":"eddycharly","description":"Brings kOps into terraform in a fully managed way","archived":false,"fork":false,"pushed_at":"2024-08-19T15:24:08.000Z","size":3461,"stargazers_count":85,"open_issues_count":33,"forks_count":20,"subscribers_count":6,"default_branch":"main","last_synced_at":"2025-04-12T07:53:30.678Z","etag":null,"topics":["kops","terraform","terraform-provider","terraform-provider-kops"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/eddycharly.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-11-02T18:00:35.000Z","updated_at":"2024-09-27T00:34:31.000Z","dependencies_parsed_at":"2024-06-18T22:48:35.651Z","dependency_job_id":"4fd945fd-7fe2-4a25-ae18-451612351a18","html_url":"https://github.com/eddycharly/terraform-provider-kops","commit_stats":null,"previous_names":[],"tags_count":103,"template":false,"template_full_name":null,"purl":"pkg:github/eddycharly/terraform-provider-kops","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/eddycharly%2Fterraform-provider-kops","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/eddycharly%2Fterraform-provider-kops/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/eddycharly%2Fterraform-provider-kops/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/eddycharly%2Fterraform-provider-kops/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/eddycharly","download_url":"https://codeload.github.com/eddycharly/terraform-provider-kops/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/eddycharly%2Fterraform-provider-kops/sbom","scorecard":{"id":366215,"data":{"date":"2025-08-11","repo":{"name":"github.com/eddycharly/terraform-provider-kops","commit":"2d1d79a3769c368b8f94d360c38c4419dcd31a66"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.7,"checks":[{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/build.yaml:1","Warn: no topLevel permission defined: .github/workflows/release.yaml:1","Warn: no topLevel permission defined: .github/workflows/verify-codegen.yaml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":5,"reason":"Found 2/4 approved changesets -- score normalized to 5","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/eddycharly/terraform-provider-kops/build.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/eddycharly/terraform-provider-kops/build.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/eddycharly/terraform-provider-kops/build.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/eddycharly/terraform-provider-kops/release.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/eddycharly/terraform-provider-kops/release.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/eddycharly/terraform-provider-kops/release.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/eddycharly/terraform-provider-kops/release.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-codegen.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/eddycharly/terraform-provider-kops/verify-codegen.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-codegen.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/eddycharly/terraform-provider-kops/verify-codegen.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-codegen.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/eddycharly/terraform-provider-kops/verify-codegen.yaml/main?enable=pin","Info:   0 out of   8 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   2 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":8,"reason":"5 out of the last 5 releases have a total of 5 signed artifacts.","details":["Info: signed release artifact: terraform-provider-kops_1.25.4_SHA256SUMS.sig: https://github.com/eddycharly/terraform-provider-kops/releases/tag/v1.25.4","Info: signed release artifact: terraform-provider-kops_1.26.0-alpha.1_SHA256SUMS.sig: https://github.com/eddycharly/terraform-provider-kops/releases/tag/v1.26.0-alpha.1","Info: signed release artifact: terraform-provider-kops_1.25.3_SHA256SUMS.sig: https://github.com/eddycharly/terraform-provider-kops/releases/tag/v1.25.3","Info: signed release artifact: terraform-provider-kops_1.25.3-alpha.1_SHA256SUMS.sig: https://github.com/eddycharly/terraform-provider-kops/releases/tag/v1.25.3-alpha.1","Info: signed release artifact: terraform-provider-kops_1.25.2-alpha.1_SHA256SUMS.sig: https://github.com/eddycharly/terraform-provider-kops/releases/tag/v1.25.2-alpha.1","Warn: release artifact v1.25.4 does not have provenance: https://api.github.com/repos/eddycharly/terraform-provider-kops/releases/110237644","Warn: release artifact v1.26.0-alpha.1 does not have provenance: https://api.github.com/repos/eddycharly/terraform-provider-kops/releases/108568014","Warn: release artifact v1.25.3 does not have provenance: https://api.github.com/repos/eddycharly/terraform-provider-kops/releases/86039315","Warn: release artifact v1.25.3-alpha.1 does not have provenance: https://api.github.com/repos/eddycharly/terraform-provider-kops/releases/86024194","Warn: release artifact v1.25.2-alpha.1 does not have provenance: https://api.github.com/repos/eddycharly/terraform-provider-kops/releases/82100245"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"23 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2022-0635","Warn: Project is vulnerable to: GO-2022-0646","Warn: Project is vulnerable to: GHSA-jq35-85cj-fj4p","Warn: Project is vulnerable to: GHSA-mq39-4gv4-mvpx","Warn: Project is vulnerable to: GO-2024-3005 / GHSA-v23v-6jw2-98fq","Warn: Project is vulnerable to: GO-2024-2512 / GHSA-xw73-rw38-6vjc","Warn: Project is vulnerable to: GO-2025-3829 / GHSA-4vq8-7jfc-9cvp","Warn: Project is vulnerable to: GO-2024-3250 / GHSA-29wx-vh33-7x7r","Warn: Project is vulnerable to: GO-2025-3553 / GHSA-mh63-6h87-95cp","Warn: Project is vulnerable to: GO-2023-2402 / GHSA-45x7-px36-x8w8","Warn: Project is vulnerable to: GO-2024-3321 / GHSA-v778-237x-gjrc","Warn: Project is vulnerable to: GO-2025-3487 / GHSA-hcg3-q754-cr77","Warn: Project is vulnerable to: GO-2023-1988 / GHSA-2wrh-6pvc-2jm9","Warn: Project is vulnerable to: GO-2023-2102 / GHSA-4374-p667-p6c8","Warn: Project is vulnerable to: GO-2023-2153 / GHSA-m425-mq94-257g / GHSA-qppj-fm5r-hxr3","Warn: Project is vulnerable to: GO-2024-2687 / GHSA-4v7x-pqxf-cx7m","Warn: Project is vulnerable to: GO-2024-3333","Warn: Project is vulnerable to: GO-2025-3503 / GHSA-qxp5-gwg8-xv66","Warn: Project is vulnerable to: GO-2025-3595 / GHSA-vvgc-356p-c3xw","Warn: Project is vulnerable to: GO-2025-3488 / GHSA-6v2p-p543-phr9","Warn: Project is vulnerable to: GO-2024-2611 / GHSA-8r3f-844c-mc37","Warn: Project is vulnerable to: GO-2024-2631 / GHSA-c5q2-7r4c-mv6g","Warn: Project is vulnerable to: GO-2023-2170"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-18T11:53:43.304Z","repository_id":37013203,"created_at":"2025-08-18T11:53:43.304Z","updated_at":"2025-08-18T11:53:43.304Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30366051,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-10T21:41:54.280Z","status":"ssl_error","status_checked_at":"2026-03-10T21:40:59.357Z","response_time":106,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["kops","terraform","terraform-provider","terraform-provider-kops"],"created_at":"2024-10-11T06:20:39.428Z","updated_at":"2026-03-11T01:31:02.251Z","avatar_url":"https://github.com/eddycharly.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# terraform-provider-kops\n\n[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://github.com/eddycharly/terraform-provider-kops/blob/master/LICENSE)\n[![Go Report Card](https://goreportcard.com/badge/eddycharly/terraform-provider-kops)](https://goreportcard.com/report/eddycharly/terraform-provider-kops)\n\n`terraform-provider-kops` brings [kOps](https://github.com/kubernetes/kops)\ninto terraform in a fully managed way, enabling idempotency through direct\nintegration with the kOps api:\n- No `local_exec`\n- No yaml templating\n- No CLI invocations\n\n... just **pure go code.**\n\nCurrently using kOps `v1.26.4` and compatible with terraform `0.15` and higher.\n\n**NOTES**\n- For now, provisioning the network is not supported. The network must\nbe created separately and given to the provider through cluster attribute\n`network_id` and subnets attributes `provider_id`.\n- The provider has only been tested with AWS, Calico and Cilium networking.\nIf you use it with another cloud or networking provider, please let us know so\nthat we can help troubleshooting if necessary and update the docs.\n\n## Why use it\n\nkOps is an amazing tool but it can be challenging to integrate in an IAC\n(infrastructure as code) stack.\n\nTypical solutions usually involve running kOps CLI in shell scripts or generating\nkOps templates manually and force syncing them with the kOps store.\n\nIn most cases, getting something idempotent is difficult because you need to\nsomewhat keep the state of the cluster and are responsible for deleting obsolete\ninstange groups for example.\n\nThis is where `terraform` shines in, state management. This provider takes care\nof creating, updating and deleting instance groups as they evolve over time.\n\nEven if kOps provides `kops update cluster --target terraform` to create the\nterraform configuration for a kOps cluster, it is still necessary to run\n`kops rolling-update cluster` to recycle instance groups when something changes\nin the cluster.\nWith this provider, this is all taken care of and you should never need to invoke\nkOps manually.\n\n## How does it work\n\nThe provider declares resources to declare the state of the cluster:\n- [kops_cluster](/docs/resources/cluster.md) defines the desired state of a cluster\n- [kops_instance_group](/docs/resources/instance_group.md) defines the desired state of a cluster instance group\n\nThe provider also declares data sources to fetch the state of the cluster and\nuse it in your terraform code:\n- [kops_cluster](/docs/data-sources/cluster.md) fetches the current state of a cluster\n- [kops_instance_group](/docs/data-sources/instance_group.md) fetches the current state of a cluster instance group\n- [kops_cluster_status](/docs/data-sources/cluster_status.md) fetches the current status of a cluster\n- [kops_kube_config](/docs/data-sources/kube_config.md) fetches the kube config infos of a cluster\n\nFinally, a special resource takes care of the cluster lifecyle:\n- [kops_cluster_updater](/docs/resources/cluster_updater.md) manages cluster updates and/or rolling updates\n\n[Provider configuration](/docs/guides/provider.md) holds cloud provider\nauthentication settings, currently only AWS is supported.\n\n## Docs\n\nThe full documentation is available in the [docs](/docs/index.md) folder or\non the [terraform registry](https://registry.terraform.io/providers/eddycharly/kops/latest/docs)\nprovider page.\n\n## Installing the provider\n\nTo install the provider, add it in the terraform `required_providers` set.\n\n```hcl\nterraform {\n  required_providers {\n    kops = {\n      source  = \"eddycharly/kops\"\n    }\n  }\n}\n```\n\n## Building the provider\n\nTo build the provider, clone this repository and run the following command:\n\n```shell\nmake all\n```\n\nIf you want to install the built provider after building it, run the following\ncommand instead (working on linux and macos):\n\n```shell\nmake install\n```\n\n## Using the provider\n\nTo use the provider you will need to register it in your terraform code:\n\n```hcl\nterraform {\n  required_providers {\n    kops = {\n      source   = \"github/eddycharly/kops\"\n      versions = [\"0.0.1\"]\n    }\n  }\n}\n\nprovider \"kops\" {\n  state_store = \"s3://cluster.example.com\"\n  // optionally set up your cloud provider access config\n  aws {\n    profile = \"example_profile\"\n  }\n}\n```\n\n## Example usage\n\n```hcl\nlocals {\n  masterType  = \"t3.medium\"\n  nodeType    = \"t3.medium\"\n  clusterName = \"cluster.example.com\"\n  dnsZone     = \"example.com\"\n  vpcId       = \"vpc-id\"\n  privateSubnets = [\n    { subnetId = \"private-subnet-0\", zone = \"zone-0\" },\n    { subnetId = \"private-subnet-1\", zone = \"zone-1\" },\n    { subnetId = \"private-subnet-2\", zone = \"zone-2\" }\n  ]\n  utilitySubnets = [\n    { subnetId = \"utility-subnet-0\", zone = \"zone-0\" },\n    { subnetId = \"utility-subnet-1\", zone = \"zone-1\" },\n    { subnetId = \"utility-subnet-2\", zone = \"zone-2\" }\n  ]\n}\n\nresource \"kops_cluster\" \"cluster\" {\n  name               = local.clusterName\n  admin_ssh_key      = file(\"${path.module}/../dummy_ssh.pub\")\n  kubernetes_version = \"stable\"\n  dns_zone           = local.dnsZone\n  network_id         = local.vpcId\n\n  cloud_provider {\n    aws {}\n  }\n\n  iam {\n    allow_container_registry = true\n  }\n\n  networking {\n    calico {}\n  }\n\n  topology {\n    masters = \"private\"\n    nodes   = \"private\"\n    dns {\n      type = \"Private\"\n    }\n  }\n\n  # private subnets\n  subnet {\n    name        = \"private-0\"\n    type        = \"Private\"\n    provider_id = local.privateSubnets[0].subnetId\n    zone        = local.privateSubnets[0].zone\n  }\n  subnet {\n    name        = \"private-1\"\n    type        = \"Private\"\n    provider_id = local.privateSubnets[1].subnetId\n    zone        = local.privateSubnets[1].zone\n  }\n  subnet {\n    name        = \"private-2\"\n    type        = \"Private\"\n    provider_id = local.privateSubnets[2].subnetId\n    zone        = local.privateSubnets[2].zone\n  }\n  subnet {\n    name        = \"utility-0\"\n    type        = \"Utility\"\n    provider_id = local.utilitySubnets[0].subnetId\n    zone        = local.utilitySubnets[0].zone\n  }\n  subnet {\n    name        = \"utility-1\"\n    type        = \"Utility\"\n    provider_id = local.utilitySubnets[1].subnetId\n    zone        = local.utilitySubnets[1].zone\n  }\n  subnet {\n    name        = \"utility-2\"\n    type        = \"Utility\"\n    provider_id = local.utilitySubnets[2].subnetId\n    zone        = local.utilitySubnets[2].zone\n  }\n\n  # etcd clusters\n  etcd_cluster {\n    name = \"main\"\n    member {\n      name           = \"master-0\"\n      instance_group = \"master-0\"\n    }\n    member {\n      name           = \"master-1\"\n      instance_group = \"master-1\"\n    }\n    member {\n      name           = \"master-2\"\n      instance_group = \"master-2\"\n    }\n  }\n  etcd_cluster {\n    name = \"events\"\n    member {\n      name           = \"master-0\"\n      instance_group = \"master-0\"\n    }\n    member {\n      name           = \"master-1\"\n      instance_group = \"master-1\"\n    }\n    member {\n      name           = \"master-2\"\n      instance_group = \"master-2\"\n    }\n  }\n}\n\nresource \"kops_instance_group\" \"master-0\" {\n  cluster_name = kops_cluster.cluster.id\n  name         = \"master-0\"\n  role         = \"Master\"\n  min_size     = 1\n  max_size     = 1\n  machine_type = local.masterType\n  subnets      = [\"private-0\"]\n}\n\nresource \"kops_instance_group\" \"master-1\" {\n  cluster_name = kops_cluster.cluster.id\n  name         = \"master-1\"\n  role         = \"Master\"\n  min_size     = 1\n  max_size     = 1\n  machine_type = local.masterType\n  subnets      = [\"private-1\"]\n}\n\nresource \"kops_instance_group\" \"master-2\" {\n  cluster_name = kops_cluster.cluster.id\n  name         = \"master-2\"\n  role         = \"Master\"\n  min_size     = 1\n  max_size     = 1\n  machine_type = local.masterType\n  subnets      = [\"private-2\"]\n}\n\nresource \"kops_instance_group\" \"node-0\" {\n  cluster_name = kops_cluster.cluster.id\n  name         = \"node-0\"\n  role         = \"Node\"\n  min_size     = 1\n  max_size     = 2\n  machine_type = local.nodeType\n  subnets      = [\"private-0\"]\n}\n\nresource \"kops_instance_group\" \"node-1\" {\n  cluster_name = kops_cluster.cluster.id\n  name         = \"node-1\"\n  role         = \"Node\"\n  min_size     = 1\n  max_size     = 2\n  machine_type = local.nodeType\n  subnets      = [\"private-1\"]\n}\n\nresource \"kops_instance_group\" \"node-2\" {\n  cluster_name = kops_cluster.cluster.id\n  name         = \"node-2\"\n  role         = \"Node\"\n  min_size     = 1\n  max_size     = 2\n  machine_type = local.nodeType\n  subnets      = [\"private-2\"]\n}\n\nresource \"kops_cluster_updater\" \"updater\" {\n  cluster_name = kops_cluster.cluster.id\n\n  keepers = {\n    cluster  = kops_cluster.cluster.revision\n    master-0 = kops_instance_group.master-0.revision\n    master-1 = kops_instance_group.master-1.revision\n    master-2 = kops_instance_group.master-2.revision\n    node-0   = kops_instance_group.node-0.revision\n    node-1   = kops_instance_group.node-1.revision\n    node-2   = kops_instance_group.node-2.revision\n  }\n}\n```\n\nMore examples are available in the `/examples` folder:\n- [Basic example](./examples/basic)\n- [Aws profile example](./examples/aws-profile)\n- [Aws assume role](./examples/aws-assume-role)\n- [Bastion example](./examples/bastion)\n\n## Importing an existing cluster\n\nYou can import an existing cluster by creating a `kops_cluster` configuration\nand running the `terraform import` command:\n\n1. Create a terraform configuration:\n\n    ```hcl\n    provider \"kops\" {\n      state_store = \"s3://cluster.example.com\"\n    }\n\n    resource \"kops_cluster\" \"cluster\" {\n      name        = \"cluster.example.com\"\n      \n      // ....\n    }\n    ```\n\n1. Run `terraform import`:\n\n    ```shell\n    terraform import kops_cluster.cluster cluster.example.com\n    ```\n\n## Importing an existing instance group\n\nYou can import an existing cluster by creating a `kops_instance_group` configuration\nand running the `terraform import` command:\n\n1. Create a terraform configuration:\n\n    ```hcl\n    provider \"kops\" {\n      state_store = \"s3://cluster.example.com\"\n    }\n\n    resource \"kops_instance_group\" \"ig-0\" {\n      cluster_name = \"cluster.example.com\"\n      name         = \"ig-0\"\n      \n      // ....\n    }\n    ```\n\n1. Run `terraform import`:\n\n    ```shell\n    terraform import kops_instance_group.ig-0 cluster.example.com/ig-0\n    ```\n\n**NOTE**: the id of the instance group to be imported must be given in the \n`cluster name/instance group name` format.\n\n## Getting kubeconfig file\n\nTo retrieve the `kubeconfig` file for the cluster, run the following command:\n\n```shell\nkops export kubecfg --admin --name cluster.example.com --state s3://cluster.example.com\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Feddycharly%2Fterraform-provider-kops","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Feddycharly%2Fterraform-provider-kops","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Feddycharly%2Fterraform-provider-kops/lists"}