<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Forem: Tuan Anh Tran</title>
    <description>The latest articles on Forem by Tuan Anh Tran (@tuananh_org).</description>
    <link>https://forem.com/tuananh_org</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F578635%2Fc68fc461-6e94-47ae-8462-4082260fa514.jpeg</url>
      <title>Forem: Tuan Anh Tran</title>
      <link>https://forem.com/tuananh_org</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://forem.com/feed/tuananh_org"/>
    <language>en</language>
    <item>
      <title>aws-cli v2: how much smaller can it get? Answer: a lot smaller :)</title>
      <dc:creator>Tuan Anh Tran</dc:creator>
      <pubDate>Sun, 19 Mar 2023 16:54:26 +0000</pubDate>
      <link>https://forem.com/aws-builders/aws-cli-v2-how-much-smaller-can-it-get-answer-a-lot-smaller--22fl</link>
      <guid>https://forem.com/aws-builders/aws-cli-v2-how-much-smaller-can-it-get-answer-a-lot-smaller--22fl</guid>
      <description>&lt;p&gt;Pulling the official aws-cli image, I got a huge 374MB image.&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;

docker images | grep amazon
amazon/aws-cli                                              latest            abb3d3272080   3 days ago      374MB


&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;It's rather big for a CLI and so I thought: "Maybe I can make it smaller".&lt;/p&gt;

&lt;h2&gt;
  
  
  Entering Wolfi
&lt;/h2&gt;

&lt;p&gt;Wolfi is a project sponsored by Chainguard. Wolfi is described as:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;a href="https://github.com/wolfi-dev/" rel="noopener noreferrer"&gt;Wolfi&lt;/a&gt; is a stripped-down distro designed for the cloud-native era.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Well, you can think of it like Google's &lt;a href="https://github.com/GoogleContainerTools/distroless" rel="noopener noreferrer"&gt;distroless&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The reason I want to select Wolfi is because of a bunch of reasons:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Better SBOM support. Well, not all the SBOMs are created equally and what's better than building everything from sources and create SBOM from there.&lt;/li&gt;
&lt;li&gt;Multi-arch (amd64, arm64 are must but maybe armv7 as well?)&lt;/li&gt;
&lt;li&gt;Smaller image size.&lt;/li&gt;
&lt;li&gt;Signed and verifiable :)&lt;/li&gt;
&lt;li&gt;Secure. Let's aim for that sweet 0 CVE.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  aws-cli v2
&lt;/h2&gt;

&lt;p&gt;aws-cli v2 is powered by a bunch of C project like &lt;a href="https://github.com/awslabs/aws-c-http" rel="noopener noreferrer"&gt;aws-c-http&lt;/a&gt;, &lt;a href="https://github.com/awslabs/aws-c-auth" rel="noopener noreferrer"&gt;aws-c-auth&lt;/a&gt;, etc... and so I need to package those first.&lt;/p&gt;

&lt;p&gt;What I don't quite understand is AWS's decision to still use Python as frontend for the CLI. And packaging Python packages is like going down the rabbit hole.&lt;/p&gt;

&lt;p&gt;I'm going to use &lt;a href="https://github.com/chainguard-dev/melange" rel="noopener noreferrer"&gt;melange&lt;/a&gt; for packaging. I write melange package's manifest in YAML and melange spits out APK file for me.&lt;/p&gt;

&lt;p&gt;Here's what a package build file looks like with melange&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;

&lt;span class="na"&gt;package&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;aws-c-http&lt;/span&gt;
  &lt;span class="na"&gt;version&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;0.7.5&lt;/span&gt;
  &lt;span class="na"&gt;epoch&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;
  &lt;span class="na"&gt;description&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;AWS C99 implementation of the HTTP/1.1 and HTTP/2 specifications&lt;/span&gt;
  &lt;span class="na"&gt;copyright&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;license&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Apache-2.0&lt;/span&gt;
&lt;span class="na"&gt;environment&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;contents&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;keyring&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;https://packages.wolfi.dev/os/wolfi-signing.rsa.pub&lt;/span&gt;
    &lt;span class="na"&gt;repositories&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;https://packages.wolfi.dev/os&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;@local&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;./packages'&lt;/span&gt;
    &lt;span class="na"&gt;packages&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;aws-c-cal-dev@local&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;aws-c-common-dev@local&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;aws-c-compression-dev@local&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;aws-c-io-dev@local&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;build-base&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;busybox&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;ca-certificates-bundle&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;cmake&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;s2n-tls-dev@local&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;samurai&lt;/span&gt;
&lt;span class="na"&gt;pipeline&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;uses&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;fetch&lt;/span&gt;
    &lt;span class="na"&gt;with&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="na"&gt;expected-sha512&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;90bfd0abfce8727bd4ef6e9a016e6183c2c4349c2d6e4cc02b932f5109ceb3476d79b853e74ca4888b768f44eba9ae953ca5e9b900704a2a3370a200c0168c02&lt;/span&gt;
      &lt;span class="na"&gt;uri&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;https://github.com/awslabs/aws-c-http/archive/refs/tags/v${{package.version}}.tar.gz&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;runs&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;|&lt;/span&gt;
      &lt;span class="s"&gt;if [ "$CBUILD" != "$CHOST" ]; then&lt;/span&gt;
        &lt;span class="s"&gt;CMAKE_CROSSOPTS="-DCMAKE_SYSTEM_NAME=Linux -DCMAKE_HOST_SYSTEM_NAME=Linux"&lt;/span&gt;
      &lt;span class="s"&gt;fi&lt;/span&gt;
      &lt;span class="s"&gt;CFLAGS="$CFLAGS -flto=auto" \&lt;/span&gt;
      &lt;span class="s"&gt;CXXFLAGS="$CXXFLAGS -flto=auto" \&lt;/span&gt;
      &lt;span class="s"&gt;cmake -B build -G Ninja \&lt;/span&gt;
        &lt;span class="s"&gt;-DCMAKE_INSTALL_PREFIX=/usr \&lt;/span&gt;
        &lt;span class="s"&gt;-DCMAKE_INSTALL_LIBDIR=/usr/lib \&lt;/span&gt;
        &lt;span class="s"&gt;-DBUILD_SHARED_LIBS=True \&lt;/span&gt;
        &lt;span class="s"&gt;-DCMAKE_BUILD_TYPE=None \&lt;/span&gt;
        &lt;span class="s"&gt;-DBUILD_TESTING="$(want_check &amp;amp;&amp;amp; echo ON || echo OFF)" \&lt;/span&gt;
        &lt;span class="s"&gt;$CMAKE_CROSSOPTS&lt;/span&gt;
      &lt;span class="s"&gt;cmake --build build&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;runs&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;|&lt;/span&gt;
      &lt;span class="s"&gt;DESTDIR="${{targets.destdir}}" cmake --install build&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;uses&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;strip&lt;/span&gt;
&lt;span class="na"&gt;subpackages&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;aws-c-http-dev&lt;/span&gt;
    &lt;span class="na"&gt;pipeline&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;uses&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;split/dev&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;runs&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;|&lt;/span&gt;
          &lt;span class="s"&gt;mkdir -p "${{targets.subpkgdir}}"/usr/lib&lt;/span&gt;
          &lt;span class="s"&gt;mv "${{targets.destdir}}"/usr/lib/aws-c-http "${{targets.subpkgdir}}"/usr/lib/&lt;/span&gt;
    &lt;span class="na"&gt;dependencies&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="na"&gt;runtime&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
        &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;aws-c-http&lt;/span&gt;
    &lt;span class="na"&gt;description&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;aws-c-http dev&lt;/span&gt;



&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;I also need to package a bunch of Python libs like &lt;code&gt;py3-certifi&lt;/code&gt;, &lt;code&gt;py3-distro&lt;/code&gt;, etc... because they are not available on Wolfi yet.&lt;/p&gt;

&lt;p&gt;Once those are done, I just need to build &lt;code&gt;aws-cli&lt;/code&gt; package, put those APK files in a final image with Chainguard's &lt;a href="https://github.com/chainguard-dev/apko" rel="noopener noreferrer"&gt;apko&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Preliminary result
&lt;/h2&gt;

&lt;p&gt;The early result looks very promising. The final image is much smaller. 50% smaller to be precised. And I mean without any optimizations at all. I haven't even split the docs into their own packages yet.&lt;/p&gt;

&lt;p&gt;Let's look at it.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fqnnb6d3ntoxeh290id5h.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fqnnb6d3ntoxeh290id5h.png" alt="new aws-cli image size"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;186MB vs the original 374MB. A whooping 188MB stripped off from the official aws-cli image. That's 50% size reduction.&lt;/p&gt;

&lt;p&gt;Are you sure it's even working :D&lt;/p&gt;

&lt;h2&gt;
  
  
  Final
&lt;/h2&gt;

&lt;p&gt;I haven't quite done with it yet but you can try it by pulling &lt;code&gt;ghcr.io/tuananh/aws-cli&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;For now, it's still very much work-in-progress so expect things may break here and there :)&lt;/p&gt;

</description>
      <category>aws</category>
      <category>cli</category>
    </item>
    <item>
      <title>AWS - The YAML Way</title>
      <dc:creator>Tuan Anh Tran</dc:creator>
      <pubDate>Tue, 19 Oct 2021 06:47:08 +0000</pubDate>
      <link>https://forem.com/aws-builders/aws-the-yaml-way-3kgh</link>
      <guid>https://forem.com/aws-builders/aws-the-yaml-way-3kgh</guid>
      <description>&lt;p&gt;Originally posted &lt;a href="https://github.com/tuananh/aws-the-yaml-way" rel="noopener noreferrer"&gt;here on GitHub&lt;/a&gt;&lt;/p&gt;

&lt;h1&gt;
  
  
  AWS - The YAML way
&lt;/h1&gt;




&lt;p&gt;&lt;a href="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9ca35vharbyak3kgv0ef.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9ca35vharbyak3kgv0ef.jpg" alt="aws - the yaml way"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Motivation
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;I want to manage AWS infrastructure with YAML&lt;/li&gt;
&lt;li&gt;I want to use Kubernetes RBAC for authorization&lt;/li&gt;
&lt;li&gt;I want to be able to defines rules to govern my cloud resources&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  But why?
&lt;/h2&gt;

&lt;p&gt;Why not :)&lt;/p&gt;

&lt;h2&gt;
  
  
  How?
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;For (1), there's &lt;a href="https://aws.amazon.com/blogs/containers/aws-controllers-for-kubernetes-ack/" rel="noopener noreferrer"&gt;AWS Controllers for Kubernetes&lt;/a&gt; (ACK) or maybe &lt;a href="https://crossplane.io/" rel="noopener noreferrer"&gt;Crossplane&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;For (2), it's quite straight forward. If we can express AWS resources using Kubernetes CRDs, then it's done.&lt;/li&gt;
&lt;li&gt;For (3), I'm thinking &lt;a href="https://kyverno.io/" rel="noopener noreferrer"&gt;Kyverno&lt;/a&gt; or &lt;a href="https://www.openpolicyagent.org" rel="noopener noreferrer"&gt;OpenPolicyAgent&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Let's do it
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Setup the env
&lt;/h3&gt;

&lt;p&gt;I will skip the part where you setup AWS CLI and an EKS cluster Suppose that is all set and done. If not, follow the brief instructions below to setup a new EKS cluster. The easiest way IMO is to use &lt;a href="https://eksctl.io/" rel="noopener noreferrer"&gt;eksctl&lt;/a&gt; from Weaveworks.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;aws ec2 create-key-pair &lt;span class="nt"&gt;--region&lt;/span&gt; ap-southeast-1 &lt;span class="nt"&gt;--key-name&lt;/span&gt; my-yaml-eks-key

eksctl create cluster &lt;span class="se"&gt;\&lt;/span&gt;
    &lt;span class="nt"&gt;--name&lt;/span&gt; my-yaml-eks &lt;span class="se"&gt;\&lt;/span&gt;
    &lt;span class="nt"&gt;--region&lt;/span&gt; ap-southeast-1 &lt;span class="se"&gt;\&lt;/span&gt;
    &lt;span class="nt"&gt;--with-oidc&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
    &lt;span class="nt"&gt;--ssh-access&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
    &lt;span class="nt"&gt;--ssh-public-key&lt;/span&gt; my-yaml-eks-key &lt;span class="se"&gt;\&lt;/span&gt;
    &lt;span class="nt"&gt;--managed&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Wait for a bit for the cluster to be provisioned.&lt;/p&gt;

&lt;p&gt;There will be 2 CloudFormation stacks being provisioned so it might take awhile. If something goes wrong (disconnection, etc..), you can check with this command below&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;eksctl utils describe-stacks &lt;span class="nt"&gt;--region&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;ap-southeast-1 &lt;span class="nt"&gt;--cluster&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;my-yaml-eks
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;2021-10-18 22:35:28 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  eksctl version 0.70.0
2021-10-18 22:35:28 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  using region ap-southeast-1
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  setting availability zones to &lt;span class="o"&gt;[&lt;/span&gt;ap-southeast-1a ap-southeast-1b ap-southeast-1c]
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  subnets &lt;span class="k"&gt;for &lt;/span&gt;ap-southeast-1a - public:192.168.0.0/19 private:192.168.96.0/19
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  subnets &lt;span class="k"&gt;for &lt;/span&gt;ap-southeast-1b - public:192.168.32.0/19 private:192.168.128.0/19
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  subnets &lt;span class="k"&gt;for &lt;/span&gt;ap-southeast-1c - public:192.168.64.0/19 private:192.168.160.0/19
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  nodegroup &lt;span class="s2"&gt;"ng-5c441b7d"&lt;/span&gt; will use &lt;span class="s2"&gt;""&lt;/span&gt; &lt;span class="o"&gt;[&lt;/span&gt;AmazonLinux2/1.20]
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  using EC2 key pair %!q&lt;span class="o"&gt;(&lt;/span&gt;&lt;span class="k"&gt;*&lt;/span&gt;&lt;span class="nv"&gt;string&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&amp;lt;nil&amp;gt;&lt;span class="o"&gt;)&lt;/span&gt;
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  using Kubernetes version 1.20
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  creating EKS cluster &lt;span class="s2"&gt;"my-yaml-eks"&lt;/span&gt; &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="s2"&gt;"ap-southeast-1"&lt;/span&gt; region with managed nodes
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  will create 2 separate CloudFormation stacks &lt;span class="k"&gt;for &lt;/span&gt;cluster itself and the initial managed nodegroup
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  &lt;span class="k"&gt;if &lt;/span&gt;you encounter any issues, check CloudFormation console or try &lt;span class="s1"&gt;'eksctl utils describe-stacks --region=ap-southeast-1 --cluster=my-yaml-eks'&lt;/span&gt;
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  CloudWatch logging will not be enabled &lt;span class="k"&gt;for &lt;/span&gt;cluster &lt;span class="s2"&gt;"my-yaml-eks"&lt;/span&gt; &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="s2"&gt;"ap-southeast-1"&lt;/span&gt;
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  you can &lt;span class="nb"&gt;enable &lt;/span&gt;it with &lt;span class="s1"&gt;'eksctl utils update-cluster-logging --enable-types={SPECIFY-YOUR-LOG-TYPES-HERE (e.g. all)} --region=ap-southeast-1 --cluster=my-yaml-eks'&lt;/span&gt;
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  Kubernetes API endpoint access will use default of &lt;span class="o"&gt;{&lt;/span&gt;&lt;span class="nv"&gt;publicAccess&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nb"&gt;true&lt;/span&gt;, &lt;span class="nv"&gt;privateAccess&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nb"&gt;false&lt;/span&gt;&lt;span class="o"&gt;}&lt;/span&gt; &lt;span class="k"&gt;for &lt;/span&gt;cluster &lt;span class="s2"&gt;"my-yaml-eks"&lt;/span&gt; &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="s2"&gt;"ap-southeast-1"&lt;/span&gt;
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]
2 sequential tasks: &lt;span class="o"&gt;{&lt;/span&gt; create cluster control plane &lt;span class="s2"&gt;"my-yaml-eks"&lt;/span&gt;,
    2 sequential sub-tasks: &lt;span class="o"&gt;{&lt;/span&gt;
        4 sequential sub-tasks: &lt;span class="o"&gt;{&lt;/span&gt;
            &lt;span class="nb"&gt;wait &lt;/span&gt;&lt;span class="k"&gt;for &lt;/span&gt;control plane to become ready,
            associate IAM OIDC provider,
            2 sequential sub-tasks: &lt;span class="o"&gt;{&lt;/span&gt;
                create IAM role &lt;span class="k"&gt;for &lt;/span&gt;serviceaccount &lt;span class="s2"&gt;"kube-system/aws-node"&lt;/span&gt;,
                create serviceaccount &lt;span class="s2"&gt;"kube-system/aws-node"&lt;/span&gt;,
            &lt;span class="o"&gt;}&lt;/span&gt;,
            restart daemonset &lt;span class="s2"&gt;"kube-system/aws-node"&lt;/span&gt;,
        &lt;span class="o"&gt;}&lt;/span&gt;,
        create managed nodegroup &lt;span class="s2"&gt;"ng-5c441b7d"&lt;/span&gt;,
    &lt;span class="o"&gt;}&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
2021-10-18 22:35:29 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  building cluster stack &lt;span class="s2"&gt;"eksctl-my-yaml-eks-cluster"&lt;/span&gt;
2021-10-18 22:35:30 &lt;span class="o"&gt;[&lt;/span&gt;ℹ]  deploying stack &lt;span class="s2"&gt;"eksctl-my-yaml-eks-cluster"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Once it's done. Make sure the cluster is accessible&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fvfpkjt3pyduqvf0woeiq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fvfpkjt3pyduqvf0woeiq.png" alt="Image description"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Setup Crossplane
&lt;/h3&gt;

&lt;p&gt;At first, I plan to use &lt;a href="https://aws.amazon.com/blogs/containers/aws-controllers-for-kubernetes-ack/" rel="noopener noreferrer"&gt;ACK&lt;/a&gt; but then I remember a friend of mine talked about Crossplane the other day so I want to give it a try. Bonus point, it works with multiple cloud providers :)&lt;/p&gt;

&lt;p&gt;I'm going to use Helm so make sure you have it installed. Simply follow the official &lt;a href="https://crossplane.io/docs/v1.4/getting-started/install-configure.html" rel="noopener noreferrer"&gt;installation instructions on Crossplane website here&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;As of this post, &lt;code&gt;1.4.1&lt;/code&gt; is the latest chart version.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;kubectl create namespace crossplane-system

helm repo add crossplane-stable https://charts.crossplane.io/stable
helm repo update
helm &lt;span class="nb"&gt;install &lt;/span&gt;crossplane &lt;span class="nt"&gt;--namespace&lt;/span&gt; crossplane-system crossplane-stable/crossplane &lt;span class="nt"&gt;--version&lt;/span&gt; 1.4.1
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;NAME: crossplane
LAST DEPLOYED: Mon Oct 18 23:05:25 2021
NAMESPACE: crossplane-system
STATUS: deployed
REVISION: 1
TEST SUITE: None
NOTES:
Release: crossplane

Chart Name: crossplane
Chart Description: Crossplane is an open source Kubernetes add-on that enables platform teams to assemble infrastructure from multiple vendors, and expose higher level self-service APIs for application teams to consume.
Chart Version: 1.4.1
Chart Application Version: 1.4.1

Kube Version: v1.20.7-eks-d88609
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Check the status&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;helm list &lt;span class="nt"&gt;-n&lt;/span&gt; crossplane-system
kubectl get all &lt;span class="nt"&gt;-n&lt;/span&gt; crossplane-system
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fyuft91257kzrckol30k0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fyuft91257kzrckol30k0.png" alt="Image description"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Also, make sure to install the Crossplane CLI.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-sL&lt;/span&gt; https://raw.githubusercontent.com/crossplane/crossplane/master/install.sh | sh
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Setup Crossplane provider for AWS
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;apiVersion&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;pkg.crossplane.io/v1&lt;/span&gt;
&lt;span class="na"&gt;kind&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Provider&lt;/span&gt;
&lt;span class="na"&gt;metadata&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;provider-aws&lt;/span&gt;
&lt;span class="na"&gt;spec&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;package&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;crossplane/provider-aws:alpha&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;After the provider is ready, apply the following next. You need to do this in 2 steps because otherwise, &lt;code&gt;ProviderConfig&lt;/code&gt; kind is unknown.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;apiVersion&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;v1&lt;/span&gt;
&lt;span class="na"&gt;stringData&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;config&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;|&lt;/span&gt;
    &lt;span class="s"&gt;[default]&lt;/span&gt;
    &lt;span class="s"&gt;aws_access_key_id = &amp;lt;your-aws-access-key-id&amp;gt;&lt;/span&gt;
    &lt;span class="s"&gt;aws_secret_access_key = &amp;lt;your-aws-secret-access-key&amp;gt;&lt;/span&gt;
&lt;span class="na"&gt;kind&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Secret&lt;/span&gt;
&lt;span class="na"&gt;metadata&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;creationTimestamp&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;null&lt;/span&gt;
  &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;aws-credentials&lt;/span&gt;
&lt;span class="nn"&gt;---&lt;/span&gt;
&lt;span class="na"&gt;apiVersion&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;aws.crossplane.io/v1beta1&lt;/span&gt;
&lt;span class="na"&gt;kind&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;ProviderConfig&lt;/span&gt;
&lt;span class="na"&gt;metadata&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;aws-provider-config&lt;/span&gt;
&lt;span class="na"&gt;spec&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;credentials&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;source&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Secret&lt;/span&gt;
    &lt;span class="na"&gt;secretRef&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="na"&gt;namespace&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;crossplane-system&lt;/span&gt;
      &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;aws-credentials&lt;/span&gt;
      &lt;span class="na"&gt;key&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;config&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Check the status of the provider&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;kubectl get providers
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fzevzk00ow257hhqco54d.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fzevzk00ow257hhqco54d.png" alt="Image description"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Let's try to create some resources on AWS
&lt;/h3&gt;

&lt;p&gt;Let's do a S3 bucket first. Make sure you do a random bucket name so that it won't conflict with an existing bucket.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;apiVersion&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;s3.aws.crossplane.io/v1beta1&lt;/span&gt;
&lt;span class="na"&gt;kind&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Bucket&lt;/span&gt;
&lt;span class="na"&gt;metadata&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;test-bucket-1923981293819238&lt;/span&gt;
  &lt;span class="na"&gt;namespace&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;default&lt;/span&gt;
&lt;span class="na"&gt;spec&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;providerConfigRef&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;aws-provider-config&lt;/span&gt;
  &lt;span class="na"&gt;forProvider&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;locationConstraint&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;ap-southeast-1&lt;/span&gt;
    &lt;span class="na"&gt;acl&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;private&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;After a few seconds, the resource status will change to &lt;code&gt;Ready&lt;/code&gt; and &lt;code&gt;Synced&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F4mrvan6r4epsha7beigi.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F4mrvan6r4epsha7beigi.png" alt="Image description"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;So that's cool. What's next? Let's trying to use OPA or Kyverno to set some rules for our newly created resources.&lt;/p&gt;

&lt;h3&gt;
  
  
  Setup Kyverno
&lt;/h3&gt;

&lt;p&gt;I'm gonna go with Kyverno here. No particular reason. I just feel OPA is too mainstream. The concept with OPA is similar. You can take it as homework for your lab session.&lt;/p&gt;

&lt;p&gt;Let's install Kyverno with Helm&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;helm repo add kyverno https://kyverno.github.io/kyverno/
helm repo update
helm &lt;span class="nb"&gt;install &lt;/span&gt;kyverno-crds kyverno/kyverno-crds &lt;span class="nt"&gt;--namespace&lt;/span&gt; kyverno &lt;span class="nt"&gt;--create-namespace&lt;/span&gt;
helm &lt;span class="nb"&gt;install &lt;/span&gt;kyverno kyverno/kyverno &lt;span class="nt"&gt;--namespace&lt;/span&gt; kyverno
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Now, let's write a simple policy. Say, we don't want to allow creating S3 bucket anywhere except in &lt;code&gt;ap-southeast-1&lt;/code&gt; region.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;apiVersion&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;kyverno.io/v1&lt;/span&gt;
&lt;span class="na"&gt;kind&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;ClusterPolicy&lt;/span&gt;
&lt;span class="na"&gt;metadata&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;allow-s3-ap-southeast-1-only&lt;/span&gt;
  &lt;span class="na"&gt;annotations&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;pod-policies.kyverno.io/autogen-controllers&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;none&lt;/span&gt;
    &lt;span class="na"&gt;policies.kyverno.io/title&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Allow creating S3 bucket in ap-southeast-1 only&lt;/span&gt;
    &lt;span class="na"&gt;policies.kyverno.io/subject&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Bucket&lt;/span&gt;
    &lt;span class="na"&gt;policies.kyverno.io/description&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;&amp;gt;-&lt;/span&gt;
      &lt;span class="s"&gt;Allow creating S3 bucket in ap-southeast-1 only&lt;/span&gt;
&lt;span class="na"&gt;spec&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;validationFailureAction&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;enforce&lt;/span&gt;
  &lt;span class="na"&gt;background&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;
  &lt;span class="na"&gt;rules&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;s3-in-ap-southeast-1-only&lt;/span&gt;
    &lt;span class="na"&gt;match&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="na"&gt;resources&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
        &lt;span class="na"&gt;kinds&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
        &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;Bucket&lt;/span&gt;
    &lt;span class="na"&gt;validate&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="na"&gt;message&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;Using&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;any&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;location&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;other&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;than&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;`ap-southeast-1`&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;is&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;not&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;allowed"&lt;/span&gt;
      &lt;span class="na"&gt;pattern&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
        &lt;span class="na"&gt;spec&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
          &lt;span class="na"&gt;forProvider&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
            &lt;span class="na"&gt;locationConstraint&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;ap-southeast-1"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Now, let's try to create a S3 bucket in &lt;code&gt;us-east-1&lt;/code&gt; region. You will be blocked by the admission controller.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="c1"&gt;# bad-s3.yaml&lt;/span&gt;
&lt;span class="na"&gt;apiVersion&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;s3.aws.crossplane.io/v1beta1&lt;/span&gt;
&lt;span class="na"&gt;kind&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Bucket&lt;/span&gt;
&lt;span class="na"&gt;metadata&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;test-bucket-091289310923801928309123&lt;/span&gt;
  &lt;span class="na"&gt;namespace&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;default&lt;/span&gt;
&lt;span class="na"&gt;spec&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;providerConfigRef&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;aws-provider-config&lt;/span&gt;
  &lt;span class="na"&gt;forProvider&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;locationConstraint&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;us-east-1&lt;/span&gt;
    &lt;span class="na"&gt;acl&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;private&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;kubectl create &lt;span class="nt"&gt;-f&lt;/span&gt; bad-s3.yaml
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fc6537sl67749riahz6cs.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fc6537sl67749riahz6cs.png" alt="Image description"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now, the policy we have here is very simple but you can do all kind of stuff with Kyverno cluster policy. It would be a cool weekend hack to convert all rules you have currently to Kyverno cluster policy. That sounds like tons of fun :)&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;I'm not going to tell you should start doing this but it's a feasible way of managing infrastructure at small scale.&lt;/p&gt;

&lt;p&gt;Also with the release of AWS Cloud Control API, the resources model is very close with the Kubernetes resources model now. I'm expecting ACK to get much much better.&lt;/p&gt;

&lt;p&gt;Have fun hacking AWS :)&lt;/p&gt;

</description>
      <category>aws</category>
      <category>devops</category>
      <category>kubernetes</category>
    </item>
  </channel>
</rss>
