-f file of kubox admin create and kubox cluster create, and the configYAML of a Cluster resource.
Start here, then use the full field list for everything else.
The smallest document that builds
cluster.yaml
string
What the cluster is called.
string
Names the Pulumi project this cluster’s stacks belong to. It cannot change once the cluster is built.
string
default:"us-east-1"
Where it is built.
AwsNodeGroup[]
The machines. You need at least one
control-plane group and usually one worker group.Growing it
Each snippet below is a fragment to merge into the document above.More workers, and the spot-instance trap
GPU nodes
GPUs need an AMI with the NVIDIA extensions, and a taint so ordinary pods do not land on them.Volumes that actually bind
awsIAMInstanceProfile is the IAM role these nodes run as. Without it, Kubox cannot create disks and your PersistentVolumeClaims stay Pending.
Which value you need depends on how you are building:
A hostname and TLS
Controllers
Controllers are installed from a registry.aws-ebs-csi-driver, aws-s3-csi-driver and runtime-class are on by default.
Roles and bindings
RbacRole and RoleBinding.
Tagging for cost reporting
Pulling from a private ECR registry
Add the credential provider extension to every node group whose workloads pull from a private ECR registry.Where the document goes
Direct
kubox admin create -f cluster.yaml builds from your machine with your own credentials, no management plane.Through a plane
kubox cluster create -f cluster.yaml asks a management plane to build it.As a resource
Inside a
Cluster resource as spec.configYAML, applied with kubectl.--plan with either command to see what would be built without building it.
Next
Every field
The complete cluster document reference, generated from the types that parse it.
Plane documents
The
plane.yaml that describes a management plane.Worked examples
GPU instances, secrets, and other advanced configuration.
Build your first cluster
The end-to-end walkthrough, with cleanup.