Creating the AWS infrastructure separately

To create the Amazon Web Services (AWS) infrastructure, you need to create a Virtual Private Cloud (VPC) and other resources for your cluster. You can use the AWS console or an infrastructure automation and provisioning tool.

For instructions to use the AWS console, see Create a VPC plus other VPC resources in the AWS Documentation.

The VPC must include private and public subnets and resources for external access, such as a network address translation (NAT) gateway and an internet gateway. In addition to the VPC, you need a private hosted zone for the ingress of your cluster. If you are creating clusters that use PrivateLink (Private or PublicAndPrivate access modes), you need an additional hosted zone for PrivateLink.

Procedure
  • Create the AWS infrastructure for your hosted cluster by using the following example configuration:

    ---
    apiVersion: v1
    kind: Namespace
    metadata:
      creationTimestamp: null
      name: clusters
    spec: {}
    status: {}
    ---
    apiVersion: v1
    data:
      .dockerconfigjson: xxxxxxxxxxx
    kind: Secret
    metadata:
      creationTimestamp: null
      labels:
        hypershift.openshift.io/safe-to-delete-with-cluster: "true"
      name: <pull_secret_name>
      namespace: clusters
    ---
    apiVersion: v1
    data:
      key: xxxxxxxxxxxxxxxxx
    kind: Secret
    metadata:
      creationTimestamp: null
      labels:
        hypershift.openshift.io/safe-to-delete-with-cluster: "true"
      name: <etcd_encryption_key_name>
      namespace: clusters
    type: Opaque
    ---
    apiVersion: v1
    data:
      id_rsa: xxxxxxxxx
      id_rsa.pub: xxxxxxxxx
    kind: Secret
    metadata:
      creationTimestamp: null
      labels:
        hypershift.openshift.io/safe-to-delete-with-cluster: "true"
      name: <ssh_key_name>
      namespace: clusters
    ---
    apiVersion: hypershift.openshift.io/v1beta1
    kind: HostedCluster
    metadata:
      creationTimestamp: null
      name: <hosted_cluster_name>
      namespace: clusters
    spec:
      autoscaling: {}
      configuration: {}
      controllerAvailabilityPolicy: SingleReplica
      dns:
        baseDomain: <dns_domain>
        privateZoneID: xxxxxxxx
        publicZoneID: xxxxxxxx
      etcd:
        managed:
          storage:
            persistentVolume:
              size: 8Gi
              storageClassName: gp3-csi
            type: PersistentVolume
        managementType: Managed
      fips: false
      infraID: <infra_id>
      issuerURL: <issuer_url>
      networking:
        clusterNetwork:
        - cidr: 10.132.0.0/14
        machineNetwork:
        - cidr: 10.0.0.0/16
        networkType: OVNKubernetes
        serviceNetwork:
        - cidr: 172.31.0.0/16
      olmCatalogPlacement: management
      platform:
        aws:
          cloudProviderConfig:
            subnet:
              id: <subnet_xxx>
            vpc: <vpc_xxx>
            zone: us-west-1b
          endpointAccess: Public
          multiArch: false
          region: us-west-1
          rolesRef:
            controlPlaneOperatorARN: arn:aws:iam::820196288204:role/<infra_id>-control-plane-operator
            imageRegistryARN: arn:aws:iam::820196288204:role/<infra_id>-openshift-image-registry
            ingressARN: arn:aws:iam::820196288204:role/<infra_id>-openshift-ingress
            kubeCloudControllerARN: arn:aws:iam::820196288204:role/<infra_id>-cloud-controller
            networkARN: arn:aws:iam::820196288204:role/<infra_id>-cloud-network-config-controller
            nodePoolManagementARN: arn:aws:iam::820196288204:role/<infra_id>-node-pool
            storageARN: arn:aws:iam::820196288204:role/<infra_id>-aws-ebs-csi-driver-controller
        type: AWS
      pullSecret:
        name: <pull_secret_name>
      release:
        image: quay.io/openshift-release-dev/ocp-release:4.16-x86_64
      secretEncryption:
        aescbc:
          activeKey:
            name: <etcd_encryption_key_name>
        type: aescbc
      services:
      - service: APIServer
        servicePublishingStrategy:
          type: LoadBalancer
      - service: OAuthServer
        servicePublishingStrategy:
          type: Route
      - service: Konnectivity
        servicePublishingStrategy:
          type: Route
      - service: Ignition
        servicePublishingStrategy:
          type: Route
      - service: OVNSbDb
        servicePublishingStrategy:
          type: Route
      sshKey:
        name: <ssh_key_name>
    status:
      controlPlaneEndpoint:
        host: ""
        port: 0
    ---
    apiVersion: hypershift.openshift.io/v1beta1
    kind: NodePool
    metadata:
      creationTimestamp: null
      name: <node_pool_name>
      namespace: clusters
    spec:
      arch: amd64
      clusterName: <hosted_cluster_name>
      management:
        autoRepair: true
        upgradeType: Replace
      nodeDrainTimeout: 0s
      platform:
        aws:
          instanceProfile: <instance_profile_name>
          instanceType: m6i.xlarge
          rootVolume:
            size: 120
            type: gp3
          subnet:
            id: <subnet_xxx>
        type: AWS
      release:
        image: quay.io/openshift-release-dev/ocp-release:4.16-x86_64
      replicas: 2
    status:
      replicas: 0
    • <pull_secret_name> specifies the name of your pull secret.

    • <etcd_encryption_key_name> specifies the name of your etcd encryption key.

    • <ssh_key_name> specifies the name of your SSH key.

    • <hosted_cluster_name> specifies the name of your hosted cluster.

    • <dns_domain> specifies your base DNS domain, such as example.com.

    • <infra_id> specifies the value that identifies the IAM resources that are associated with the hosted cluster.

    • <issuer_url> specifies your issuer URL, which ends with your infra_id value. For example, https://example-hosted-us-west-1.s3.us-west-1.amazonaws.com/example-hosted-infra-id.

    • <subnet_xxx> specifies your subnet ID. Both private and public subnets need to be tagged. For public subnets, use kubernetes.io/role/elb=1. For private subnets, use kubernetes.io/role/internal-elb=1.

    • <vpc_xxx> specifies your VPC ID.

    • <node_pool_name> specifies the name of your NodePool resource.

    • <instance_profile_name> specifies the name of your AWS instance.