- Home
- Documentation
- Kubernetes
- Resources
- xcsh_k8s_cluster (Resource)
xcsh_k8s_cluster (Resource)
Manages k8s_cluster will create the object in the storage backend for namespace metadata.namespace. in F5 Distributed Cloud.
~> Note For more information about this resource, please refer to the F5 XC API Documentation.
Example Usage
Section titled “Example Usage”# K8SCluster Resource Example# Manages k8s_cluster will create the object in the storage backend for namespace metadata.namespace.
terraform { required_version = ">= 1.0"
required_providers { xcsh = { source = "f5-sales-demo/xcsh" version = ">= 0.1.0" } }}
# Basic K8SCluster configurationresource "xcsh_k8s_cluster" "example" { name = "example-k8s-cluster" namespace = "system"}Argument Reference
Section titled “Argument Reference”-> Syntax Rule: This provider uses OneOf groups for mutually exclusive options. Fields documented as “Optional Block” use empty block syntax field_name {}, never field_name = true. Boolean attributes (like add_hsts, http_redirect) use = true/false as normal.
🔶 High Risk Operations — Some operations on this resource have high danger level. Destructive operations may require confirmation.
Minimum Configuration
Section titled “Minimum Configuration”Required fields:
namenamespace
Example (API format):
metadata: name: my-k8s-cluster namespace: demo-appspec: {}Metadata Argument Reference
Section titled “Metadata Argument Reference”• name - Required String
Name of the K8S Cluster. Must be unique within the namespace
• annotations - Optional Map
Annotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata
• description - Optional String
Human readable description for the object
• disable - Optional Bool
A value of true will administratively disable the object
• labels - Optional Map
Labels is a user defined key value map that can be attached to resources for organization and filtering
• namespace - Optional String
Namespace for the K8S Cluster. The F5 XC API restricts this resource to the system namespace; it defaults to that value and may be omitted
Spec Argument Reference
Section titled “Spec Argument Reference”-> One of the following:
• cluster_scoped_access_deny - Optional Block Defaults to map[]
Enable this option. Server applies default when omitted
• cluster_scoped_access_permit - Optional Block
Enable this option
-> One of the following:
• cluster_wide_app_list - Optional Block
Cluster Wide Application List. List of cluster wide applications
See Cluster Wide App List below for details.
-> One of the following:
• global_access_enable - Optional Block
Configuration parameter for global access enable
-> One of the following:
• insecure_registry_list - Optional Block
Docker Insecure Registry List. List of Docker insecure registries
See Insecure Registry List below for details.
-> One of the following:
• local_access_config - Optional Block
Parameters required to enable local access
See Local Access Config below for details.
• no_cluster_wide_apps - Optional Block Defaults to map[]
Enable this option. Server applies default when omitted
• no_global_access - Optional Block Defaults to map[]
Configuration parameter for no global access. Server applies default when omitted
• no_insecure_registries - Optional Block Defaults to map[]
Enable this option. Server applies default when omitted
• no_local_access - Optional Block Defaults to map[]
Configuration parameter for no local access. Server applies default when omitted
• timeouts - Optional Block
See Timeouts below for details.
-> One of the following:
• use_custom_cluster_role_bindings - Optional Block
List of active cluster role binding list for a K8S cluster
See Use Custom Cluster Role Bindings below for details.
-> One of the following:
• use_custom_cluster_role_list - Optional Block
List of active cluster role list for a K8S cluster
See Use Custom Cluster Role List below for details.
-> One of the following:
• use_custom_pod_security_admission - Optional Block
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
See Use Custom Pod Security Admission below for details.
-> One of the following:
• use_custom_psp_list - Optional Block
List of active Pod security policies for a K8S cluster
See Use Custom Psp List below for details.
• use_default_cluster_role_bindings - Optional Block Defaults to map[]
Enable this option. Server applies default when omitted
• use_default_cluster_roles - Optional Block Defaults to map[]
Enable this option. Server applies default when omitted
• use_default_pod_security_admission - Optional Block
Enable this option
• use_default_psp - Optional Block Defaults to map[]
Configuration parameter for use default psp. Server applies default when omitted
-> One of the following:
• vk8s_namespace_access_deny - Optional Block Defaults to map[]
Enable this option. Server applies default when omitted
• vk8s_namespace_access_permit - Optional Block
Enable this option
Attributes Reference
Section titled “Attributes Reference”In addition to all arguments above, the following attributes are exported:
• id - Optional String
Unique identifier for the resource
Cluster Wide App List
Section titled “Cluster Wide App List”A cluster_wide_app_list block supports the following:
• cluster_wide_apps - Optional Block
List of cluster wide applications
See Cluster Wide Apps below.
Cluster Wide App List Cluster Wide Apps
Section titled “Cluster Wide App List Cluster Wide Apps”A cluster_wide_apps block (within cluster_wide_app_list) supports the following:
• argo_cd - Optional Block
Description Parameters for Argo Continuous Deployment(CD) application
See Argo Cd below.
• dashboard - Optional Block
Description Parameters for K8S dashboard
• metrics_server - Optional Block
Description Parameters for Kubernetes Metrics Server application
• prometheus - Optional Block
Description Parameters for Prometheus server access
Cluster Wide App List Cluster Wide Apps Argo Cd
Section titled “Cluster Wide App List Cluster Wide Apps Argo Cd”Deeply nested Cd block collapsed for readability.
Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain
Section titled “Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain”Deeply nested Domain block collapsed for readability.
Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain Password
Section titled “Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain Password”Deeply nested Password block collapsed for readability.
Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain Password Blindfold Secret Info
Section titled “Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain Password Blindfold Secret Info”Deeply nested Info block collapsed for readability.
Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain Password Clear Secret Info
Section titled “Cluster Wide App List Cluster Wide Apps Argo Cd Local Domain Password Clear Secret Info”Deeply nested Info block collapsed for readability.
Insecure Registry List
Section titled “Insecure Registry List”An insecure_registry_list block supports the following:
• insecure_registries - Optional List
List of Docker insecure registries in format ‘example.com:5000’
Local Access Config
Section titled “Local Access Config”A local_access_config block supports the following:
• default_port - Optional Block
Enable this option
• local_domain - Optional String
Local K8S API server will be accessible at <site name>.<local domain>
• port - Optional Number
Use custom K8S port for API server. Available port range is less than 65000 except reserved ports
Timeouts
Section titled “Timeouts”A timeouts block supports the following:
• create - Optional String (Defaults to 30 minutes)
Used when creating the resource
• delete - Optional String (Defaults to 30 minutes)
Used when deleting the resource
• read - Optional String (Defaults to 5 minutes)
Used when retrieving the resource
• update - Optional String (Defaults to 30 minutes)
Used when updating the resource
Use Custom Cluster Role Bindings
Section titled “Use Custom Cluster Role Bindings”An use_custom_cluster_role_bindings block supports the following:
• cluster_role_bindings - Optional Block
List of active cluster role binding list for a K8S cluster
See Cluster Role Bindings below.
Use Custom Cluster Role Bindings Cluster Role Bindings
Section titled “Use Custom Cluster Role Bindings Cluster Role Bindings”Deeply nested Bindings block collapsed for readability.
Use Custom Cluster Role List
Section titled “Use Custom Cluster Role List”An use_custom_cluster_role_list block supports the following:
• cluster_roles - Optional Block
List of active cluster role list for a K8S cluster
See Cluster Roles below.
Use Custom Cluster Role List Cluster Roles
Section titled “Use Custom Cluster Role List Cluster Roles”A cluster_roles block (within use_custom_cluster_role_list) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Use Custom Pod Security Admission
Section titled “Use Custom Pod Security Admission”An use_custom_pod_security_admission block supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Use Custom Psp List
Section titled “Use Custom Psp List”An use_custom_psp_list block supports the following:
• pod_security_policies - Optional Block
List of active Pod security policies for a K8S cluster
See Pod Security Policies below.
Use Custom Psp List Pod Security Policies
Section titled “Use Custom Psp List Pod Security Policies”A pod_security_policies block (within use_custom_psp_list) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Common Types
Section titled “Common Types”The following type definitions are used throughout this resource. See the full definition here rather than repeated inline.
Object Reference {#common-object-reference}
Section titled “Object Reference {#common-object-reference}”Object references establish a direct reference from one configuration object to another in F5 Distributed Cloud. References use the format tenant/namespace/name.
| Field | Type | Description |
|---|---|---|
name | String | Name of the referenced object |
namespace | String | Namespace containing the referenced object |
tenant | String | Tenant of the referenced object (system-managed) |
Transformers {#common-transformers}
Section titled “Transformers {#common-transformers}”Transformers apply transformations to input values before matching. Multiple transformers can be applied in order.
| Value | Description |
|---|---|
LOWER_CASE | Convert to lowercase |
UPPER_CASE | Convert to uppercase |
BASE64_DECODE | Decodebase64 content |
NORMALIZE_PATH | Normalize URL path |
REMOVE_WHITESPACE | Remove whitespace characters |
URL_DECODE | Decode URL-encoded characters |
TRIM_LEFT | Trim leading whitespace |
TRIM_RIGHT | Trim trailing whitespace |
TRIM | Trim both leading and trailing whitespace |
HTTP Methods {#common-http-methods}
Section titled “HTTP Methods {#common-http-methods}”HTTP methods used for request matching.
| Value | Description |
|---|---|
ANY | Match any HTTP method |
GET | HTTP GET request |
HEAD | HTTP HEAD request |
POST | HTTP POST request |
PUT | HTTP PUT request |
DELETE | HTTP DELETE request |
CONNECT | HTTP CONNECT request |
OPTIONS | HTTP OPTIONS request |
TRACE | HTTP TRACE request |
PATCH | HTTP PATCH request |
COPY | HTTP COPY request (WebDAV) |
TLS Fingerprints {#common-tls-fingerprints}
Section titled “TLS Fingerprints {#common-tls-fingerprints}”TLS fingerprint categories for malicious client detection.
| Value | Description |
|---|---|
TLS_FINGERPRINT_NONE | No fingerprint matching |
ANY_MALICIOUS_FINGERPRINT | Match any known malicious fingerprint |
ADWARE | Adware-associated fingerprints |
DRIDEX | Dridex malware fingerprints |
GOOTKIT | Gootkit malware fingerprints |
RANSOMWARE | Ransomware-associated fingerprints |
TRICKBOT | Trickbot malware fingerprints |
IP Threat Categories {#common-ip-threat-categories}
Section titled “IP Threat Categories {#common-ip-threat-categories}”IP address threat categories for security filtering.
| Value | Description |
|---|---|
SPAM_SOURCES | Known spam sources |
WINDOWS_EXPLOITS | Windows exploit sources |
WEB_ATTACKS | Web attack sources |
BOTNETS | Known botnet IPs |
SCANNERS | Network scanner IPs |
REPUTATION | Poor reputation IPs |
PHISHING | Phishing-related IPs |
PROXY | Anonymous proxy IPs |
MOBILE_THREATS | Mobile threat sources |
TOR_PROXY | Tor exit nodes |
DENIAL_OF_SERVICE | DoS attack sources |
NETWORK | Known bad network ranges |
Import
Section titled “Import”Import is supported using the following syntax:
# Import using namespace/name formatterraform import xcsh_k8s_cluster.example system/example