You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置EKS Fargate:移除CoreDNS注解失败求助

用Terraform移除EKS CoreDNS的eks.amazonaws.com/compute-type注解

要让Fargate接管CoreDNS,必须移除绑定EC2节点的eks.amazonaws.com/compute-type注解,以下是两种可靠的Terraform实现方案:

方案一:通过Kubernetes Deployment资源管理(需导入现有资源)

步骤1:导入现有CoreDNS Deployment

先执行Terraform导入命令,关联集群中已存在的CoreDNS部署:

terraform import kubernetes_deployment.coredns kube-system/coredns

步骤2:编写Terraform配置

显式将目标注解设为null(空字符串无法删除注解,必须用null),同时通过lifecycle.ignore_changes跳过不需要Terraform管理的默认配置字段:

resource "kubernetes_deployment" "coredns" {
  metadata {
    name      = "coredns"
    namespace = "kube-system"
  }

  spec {
    template {
      metadata {
        annotations = {
          # 设为null彻底移除该注解
          "eks.amazonaws.com/compute-type" = null
        }
        # 保留CoreDNS默认标签,避免Terraform替换整个Pod模板
        labels = {
          "eks.amazonaws.com/component" = "coredns"
          "k8s-app"                     = "kube-dns"
        }
      }

      # 仅保留必要的容器定义,其余默认配置通过ignore_changes跳过
      spec {
        container {
          name  = "coredns"
          # 替换为你的EKS集群对应的CoreDNS镜像版本
          image = "602401143452.dkr.ecr.us-west-2.amazonaws.com/eks/coredns:v1.10.1-eksbuild.1"
        }
      }
    }

    selector {
      match_labels = {
        "eks.amazonaws.com/component" = "coredns"
        "k8s-app"                     = "kube-dns"
      }
    }
  }

  lifecycle {
    ignore_changes = [
      spec[0].template[0].spec[0].container[0].args,
      spec[0].template[0].spec[0].container[0].resources,
      spec[0].template[0].spec[0].dns_policy,
      spec[0].template[0].spec[0].security_context,
      # 根据实际情况添加其他不需要管理的字段
    ]
  }
}

方案二:通过Kubernetes Manifest资源实现Server-Side Apply(推荐)

无需导入现有资源,直接通过Server-Side Apply仅修改目标注解,配置更简洁:

resource "kubernetes_manifest" "coredns_remove_compute_type" {
  manifest = {
    apiVersion = "apps/v1"
    kind       = "Deployment"
    metadata = {
      name      = "coredns"
      namespace = "kube-system"
    }
    spec = {
      template = {
        metadata = {
          annotations = {
            "eks.amazonaws.com/compute-type" = null
          }
        }
      }
    }
  }

  # 启用Server-Side Apply,确保仅修改指定注解,不干扰其他默认配置
  server_side_apply {
    field_manager = "terraform"
    force_conflicts = true
  }
}

验证操作结果

执行terraform apply后,用以下命令确认注解已移除:

kubectl describe deployment coredns -n kube-system | grep -A 5 Annotations

内容的提问来源于stack exchange,提问作者sareno

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 00:20:56