Skip to content

xcsh_k8s_cluster (Resource)

Manages k8s_cluster will create the object in the storage backend for namespace metadata.namespace. in F5 Distributed Cloud.

~> Note For more information about this resource, please refer to the F5 XC API Documentation.

# K8SCluster Resource Example
# Manages k8s_cluster will create the object in the storage backend for namespace metadata.namespace.
terraform {
required_version = ">= 1.0"
required_providers {
xcsh = {
source = "f5-sales-demo/xcsh"
version = ">= 0.1.0"
}
}
}
# Basic K8SCluster configuration
resource "xcsh_k8s_cluster" "example" {
name = "example-k8s-cluster"
namespace = "system"
}

-> Syntax Rule: This provider uses OneOf groups for mutually exclusive options. Fields documented as “Optional Block” use empty block syntax field_name {}, never field_name = true. Boolean attributes (like add_hsts, http_redirect) use = true/false as normal.

🔶 High Risk Operations — Some operations on this resource have high danger level. Destructive operations may require confirmation.

Required fields:

  • name
  • namespace

Example (API format):

metadata:
name: my-k8s-cluster
namespace: demo-app
spec: {}

name - Required String
Name of the K8S Cluster. Must be unique within the namespace

annotations - Optional Map
Annotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata

description - Optional String
Human readable description for the object

disable - Optional Bool
A value of true will administratively disable the object

labels - Optional Map
Labels is a user defined key value map that can be attached to resources for organization and filtering

namespace - Optional String
Namespace for the K8S Cluster. The F5 XC API restricts this resource to the system namespace; it defaults to that value and may be omitted

-> One of the following:cluster_scoped_access_deny - Optional Block Defaults to map[]
Enable this option. Server applies default when omitted

cluster_scoped_access_permit - Optional Block
Enable this option

-> One of the following:cluster_wide_app_list - Optional Block
Cluster Wide Application List. List of cluster wide applications
See Cluster Wide App List below for details.

-> One of the following:global_access_enable - Optional Block
Configuration parameter for global access enable

-> One of the following:insecure_registry_list - Optional Block
Docker Insecure Registry List. List of Docker insecure registries
See Insecure Registry List below for details.

-> One of the following:local_access_config - Optional Block
Parameters required to enable local access
See Local Access Config below for details.

no_cluster_wide_apps - Optional Block Defaults to map[]
Enable this option. Server applies default when omitted

no_global_access - Optional Block Defaults to map[]
Configuration parameter for no global access. Server applies default when omitted

no_insecure_registries - Optional Block Defaults to map[]
Enable this option. Server applies default when omitted

no_local_access - Optional Block Defaults to map[]
Configuration parameter for no local access. Server applies default when omitted

timeouts - Optional Block
See Timeouts below for details.

-> One of the following:use_custom_cluster_role_bindings - Optional Block
List of active cluster role binding list for a K8S cluster
See Use Custom Cluster Role Bindings below for details.

-> One of the following:use_custom_cluster_role_list - Optional Block
List of active cluster role list for a K8S cluster
See Use Custom Cluster Role List below for details.

-> One of the following:use_custom_pod_security_admission - Optional Block
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
See Use Custom Pod Security Admission below for details.

-> One of the following:use_custom_psp_list - Optional Block
List of active Pod security policies for a K8S cluster
See Use Custom Psp List below for details.

use_default_cluster_role_bindings - Optional Block Defaults to map[]
Enable this option. Server applies default when omitted

use_default_cluster_roles - Optional Block Defaults to map[]
Enable this option. Server applies default when omitted

use_default_pod_security_admission - Optional Block
Enable this option

use_default_psp - Optional Block Defaults to map[]
Configuration parameter for use default psp. Server applies default when omitted

-> One of the following:vk8s_namespace_access_deny - Optional Block Defaults to map[]
Enable this option. Server applies default when omitted

vk8s_namespace_access_permit - Optional Block
Enable this option

In addition to all arguments above, the following attributes are exported:

id - Optional String
Unique identifier for the resource


A cluster_wide_app_list block supports the following:

cluster_wide_apps - Optional Block
List of cluster wide applications
See Cluster Wide Apps below.

A cluster_wide_apps block (within cluster_wide_app_list) supports the following:

argo_cd - Optional Block
Description Parameters for Argo Continuous Deployment(CD) application
See Argo Cd below.

dashboard - Optional Block
Description Parameters for K8S dashboard

metrics_server - Optional Block
Description Parameters for Kubernetes Metrics Server application

prometheus - Optional Block
Description Parameters for Prometheus server access

Cluster Wide App List Cluster Wide Apps Argo Cd

Section titled “Cluster Wide App List Cluster Wide Apps Argo Cd”

Deeply nested Cd block collapsed for readability.

Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain

Section titled “Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain”

Deeply nested Domain block collapsed for readability.

Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain Password

Section titled “Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain Password”

Deeply nested Password block collapsed for readability.

Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain Password Blindfold Secret Info

Section titled “Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain Password Blindfold Secret Info”

Deeply nested Info block collapsed for readability.

Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain Password Clear Secret Info

Section titled “Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain Password Clear Secret Info”

Deeply nested Info block collapsed for readability.

An insecure_registry_list block supports the following:

insecure_registries - Optional List
List of Docker insecure registries in format ‘example.com:5000’

A local_access_config block supports the following:

default_port - Optional Block
Enable this option

local_domain - Optional String
Local K8S API server will be accessible at <site name>.<local domain>

port - Optional Number
Use custom K8S port for API server. Available port range is less than 65000 except reserved ports

A timeouts block supports the following:

create - Optional String (Defaults to 30 minutes)
Used when creating the resource

delete - Optional String (Defaults to 30 minutes)
Used when deleting the resource

read - Optional String (Defaults to 5 minutes)
Used when retrieving the resource

update - Optional String (Defaults to 30 minutes)
Used when updating the resource

An use_custom_cluster_role_bindings block supports the following:

cluster_role_bindings - Optional Block
List of active cluster role binding list for a K8S cluster
See Cluster Role Bindings below.

Use Custom Cluster Role Bindings Cluster Role Bindings

Section titled “Use Custom Cluster Role Bindings Cluster Role Bindings”

Deeply nested Bindings block collapsed for readability.

An use_custom_cluster_role_list block supports the following:

cluster_roles - Optional Block
List of active cluster role list for a K8S cluster
See Cluster Roles below.

Use Custom Cluster Role List Cluster Roles

Section titled “Use Custom Cluster Role List Cluster Roles”

A cluster_roles block (within use_custom_cluster_role_list) supports the following:

name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name

namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace

tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant

An use_custom_pod_security_admission block supports the following:

name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name

namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace

tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant

An use_custom_psp_list block supports the following:

pod_security_policies - Optional Block
List of active Pod security policies for a K8S cluster
See Pod Security Policies below.

A pod_security_policies block (within use_custom_psp_list) supports the following:

name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name

namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace

tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant


The following type definitions are used throughout this resource. See the full definition here rather than repeated inline.

Object Reference {#common-object-reference}

Section titled “Object Reference {#common-object-reference}”

Object references establish a direct reference from one configuration object to another in F5 Distributed Cloud. References use the format tenant/namespace/name.

FieldTypeDescription
nameStringName of the referenced object
namespaceStringNamespace containing the referenced object
tenantStringTenant of the referenced object (system-managed)

Transformers apply transformations to input values before matching. Multiple transformers can be applied in order.

ValueDescription
LOWER_CASEConvert to lowercase
UPPER_CASEConvert to uppercase
BASE64_DECODEDecodebase64 content
NORMALIZE_PATHNormalize URL path
REMOVE_WHITESPACERemove whitespace characters
URL_DECODEDecode URL-encoded characters
TRIM_LEFTTrim leading whitespace
TRIM_RIGHTTrim trailing whitespace
TRIMTrim both leading and trailing whitespace

HTTP methods used for request matching.

ValueDescription
ANYMatch any HTTP method
GETHTTP GET request
HEADHTTP HEAD request
POSTHTTP POST request
PUTHTTP PUT request
DELETEHTTP DELETE request
CONNECTHTTP CONNECT request
OPTIONSHTTP OPTIONS request
TRACEHTTP TRACE request
PATCHHTTP PATCH request
COPYHTTP COPY request (WebDAV)

TLS Fingerprints {#common-tls-fingerprints}

Section titled “TLS Fingerprints {#common-tls-fingerprints}”

TLS fingerprint categories for malicious client detection.

ValueDescription
TLS_FINGERPRINT_NONENo fingerprint matching
ANY_MALICIOUS_FINGERPRINTMatch any known malicious fingerprint
ADWAREAdware-associated fingerprints
DRIDEXDridex malware fingerprints
GOOTKITGootkit malware fingerprints
RANSOMWARERansomware-associated fingerprints
TRICKBOTTrickbot malware fingerprints

IP Threat Categories {#common-ip-threat-categories}

Section titled “IP Threat Categories {#common-ip-threat-categories}”

IP address threat categories for security filtering.

ValueDescription
SPAM_SOURCESKnown spam sources
WINDOWS_EXPLOITSWindows exploit sources
WEB_ATTACKSWeb attack sources
BOTNETSKnown botnet IPs
SCANNERSNetwork scanner IPs
REPUTATIONPoor reputation IPs
PHISHINGPhishing-related IPs
PROXYAnonymous proxy IPs
MOBILE_THREATSMobile threat sources
TOR_PROXYTor exit nodes
DENIAL_OF_SERVICEDoS attack sources
NETWORKKnown bad network ranges

Import is supported using the following syntax:

Terminal window
# Import using namespace/name format
terraform import xcsh_k8s_cluster.example system/example