Resource definition
What this resource looks like
This is the CUE shape a Praxis template uses to declare a EKSCluster. The resource key is local to the template; metadata.name supplies its stable Praxis identity.
resources: {
kubernetes: {
apiVersion: "praxis.io/alpha"
kind: "EKSCluster"
metadata: name: "\(variables.name)-eks"
spec: {
region: variables.region
roleArn: variables.eksRoleArn
subnetIds: variables.eksSubnetIds
securityGroupIds: [variables.eksSecurityGroupId]
endpointPublicAccess: true
endpointPrivateAccess: true
publicAccessCidrs: ["203.0.113.0/24"]
enabledLoggingTypes: ["api", "audit", "authenticator"]
tags: _tags
}
}
}Excerpted from examples/stacks/foundation-services.cue. Open the complete example for its variables and related resources.
Desired state
Configuration
The spec block accepts 10 fields. 7 are required by the schema; fields with defaults can be omitted.
regionRequiredRegion.
stringroleArnRequiredImmutable after creation — changes surface as informational, requires-replacement diffs during reconciliation.
stringsubnetIdsRequiredSubnet IDs.
[...string]securityGroupIdsRequiredSecurity Group IDs.
[...string]versionOptionalMutable — the Kubernetes control-plane version. When omitted, AWS selects the current default. Only upgrades are supported.
stringendpointPublicAccessOptionalMutable — control-plane endpoint access. Defaults mirror AWS.
bool | *truetrueendpointPrivateAccessOptionalEndpoint Private Access.
bool | *falsefalsepublicAccessCidrsRequiredPublic Access Cidrs.
[...string]enabledLoggingTypesRequiredMutable — control-plane log types shipped to CloudWatch Logs.
[...("api" | "audit" | "authenticator" | "controllerManager" | "scheduler")]tagsRequiredTags.
[string]: stringObserved values
Outputs
Praxis records these values after observation. A dependent resource can read one with ${resources.<name>.outputs.<field>}.
arnStringnameStringstatusStringversionStringplatformVersionStringendpointStringRead without ownership
Data-source lookup
A data block reads an existing EKSCluster and exposes its outputs without storing lifecycle state. The generic filter surface accepts id, name, and tag; supported combinations depend on the AWS identity used by this resource.
data: existing: {
kind: "EKSCluster"
region: "us-west-2"
filter: {
name: "replace-with-provider-name"
}
}Adopt existing infrastructure
Import
Import persists Praxis state for an existing AWS resource. For this kind, supply: Provider identifier for the existing EKSCluster. The example starts in observed mode so Praxis reports drift without correcting it.
praxis import EKSCluster \
--id <provider-identifier> \
--region us-west-2 \
--account production \
--observeCanonical contract
Complete CUE schema
The field guide above is derived from this definition. The schema remains the source of truth for accepted values, defaults, validation constraints, and outputs in the current alpha revision.
Show the complete schema
package eks
#EKSCluster: {
apiVersion: "praxis.io/alpha"
kind: "EKSCluster"
metadata: {
// Cluster names are 1-100 chars: letters, digits, hyphens, underscores.
name: string & =~"^[a-zA-Z0-9][a-zA-Z0-9_-]{0,99}$"
labels: [string]: string
}
spec: {
region: string
// Immutable after creation — changes surface as informational,
// requires-replacement diffs during reconciliation.
roleArn: string
subnetIds: [...string]
securityGroupIds: [...string]
// Mutable — the Kubernetes control-plane version. When omitted, AWS
// selects the current default. Only upgrades are supported.
version?: string
// Mutable — control-plane endpoint access. Defaults mirror AWS.
endpointPublicAccess: bool | *true
endpointPrivateAccess: bool | *false
publicAccessCidrs: [...string]
// Mutable — control-plane log types shipped to CloudWatch Logs.
enabledLoggingTypes: [...("api" | "audit" | "authenticator" | "controllerManager" | "scheduler")]
tags: [string]: string
}
outputs?: {
arn: string
name: string
status: string
version: string
platformVersion: string
endpoint: string
}
}