clusters
Creates, updates, deletes, gets or lists a clusters resource.
Overview​
| Name | clusters |
| Type | Resource |
| Id | oci.container_engine.clusters |
Fields​
The following fields are returned by SELECT queries:
- get
- list
The cluster details.
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the cluster. (example: ocid1.cluster.oc1.iad.aaaaaaaaga3tombrmq3wgyrvmi3gcn3bmfsdizjwgy4wgyldmy3dcmtcmmyw) |
name | string | The name of the cluster. (example: My Cluster) |
availableKubernetesUpgrades | array | Available Kubernetes versions to which the clusters masters may be upgraded. |
clusterPodNetworkOptions | array | Available CNIs and network options for existing and new node pools of the cluster (x-default-description: null) |
compartmentId | string | The OCID of the compartment in which the cluster exists. (example: ocid1.compartment.oc1..aaaaaaaafqm2df7ckwmmbtdsl2bgxsw4fcpvkoojytxrqst24yww2tdmtqcq) |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
endpointConfig | object | The properties that define the network configuration for the Cluster endpoint. |
endpoints | object | The properties that define endpoints for a cluster. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
imagePolicyConfig | object | The properties that define a image verification policy. |
kmsKeyId | string | The OCID of the KMS key to be used as the master encryption key for Kubernetes secret encryption. |
kubernetesVersion | string | The version of Kubernetes running on the cluster masters. (example: v1.9.4) |
lifecycleDetails | string | Details about the state of the cluster masters. (example: waiting for node pools) |
lifecycleState | string | The state of the cluster masters. For more information, see [Monitoring Clusters](/Content/ContEng/Tasks/contengmonitoringclusters.htm) (CREATING, ACTIVE, FAILED, DELETING, DELETED, UPDATING) (example: UPDATING, x-obmcs-top-level-enum: #/definitions/ClusterLifecycleState) |
metadata | object | The properties that define meta data for a cluster. |
openIdConnectDiscoveryEndpoint | string | The cluster-specific OpenID Connect Discovery endpoint (example: https:​//objectstorage.us-ashburn-1.oci.customer-oci.com/n/id9y6mi8tcky/b/oidc/o/a1936058-8b1c-4527-b21c-6766527236f6/.well-known/openid-configuration) |
openIdConnectDiscoveryKey | string | The cluster-specific OpenID Connect Discovery Key to derive the DiscoveryEndpoint (example: a1936058-8b1c-4527-b21c-6766527236f6) |
options | object | The properties that define extra options for a cluster. |
systemTags | object | Usage of system tag keys. These predefined keys are scoped to namespaces. Example: {"orcl-cloud": {"free-tier-retained": "true"}} |
type | string | Type of cluster (BASIC_CLUSTER, ENHANCED_CLUSTER) (example: ENHANCED_CLUSTER, x-obmcs-top-level-enum: #/definitions/ClusterType) |
vcnId | string | The OCID of the virtual cloud network (VCN) in which the cluster exists. (example: ocid1.vcn.oc1.iad.aaaaaaaa5e3hn7hk6y63awlhbvlhsumkn5p3ficbjcevbnoylvptcpkxtsaa) |
The properties that define a cluster summary.
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the cluster. (example: ocid1.cluster.oc1.iad.aaaaaaaaga3tombrmq3wgyrvmi3gcn3bmfsdizjwgy4wgyldmy3dcmtcmmyw) |
name | string | The name of the cluster. (example: My Cluster Summary) |
availableKubernetesUpgrades | array | Available Kubernetes versions to which the clusters masters may be upgraded. |
clusterPodNetworkOptions | array | Available CNIs and network options for existing and new node pools of the cluster (x-default-description: null) |
compartmentId | string | The OCID of the compartment in which the cluster exists. (example: ocid1.compartment.oc1..aaaaaaaafqm2df7ckwmmbtdsl2bgxsw4fcpvkoojytxrqst24yww2tdmtqcq) |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
endpointConfig | object | The properties that define the network configuration for the Cluster endpoint. |
endpoints | object | The properties that define endpoints for a cluster. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
imagePolicyConfig | object | The properties that define a image verification policy. |
kubernetesVersion | string | The version of Kubernetes running on the cluster masters. (example: v1.9.4) |
lifecycleDetails | string | Details about the state of the cluster masters. (example: waiting for node pools) |
lifecycleState | string | The state of the cluster masters. For more information, see [Monitoring Clusters](/Content/ContEng/Tasks/contengmonitoringclusters.htm) (CREATING, ACTIVE, FAILED, DELETING, DELETED, UPDATING) (example: UPDATING, x-obmcs-top-level-enum: #/definitions/ClusterLifecycleState) |
metadata | object | The properties that define meta data for a cluster. |
options | object | The properties that define extra options for a cluster. |
systemTags | object | Usage of system tag keys. These predefined keys are scoped to namespaces. Example: {"orcl-cloud": {"free-tier-retained": "true"}} |
type | string | Type of cluster. Values can be BASIC_CLUSTER or ENHANCED_CLUSTER. For more information, see [Cluster Types](/Content/ContEng/Tasks/contengcomparingenhancedwithbasicclusters_topic.htm) (BASIC_CLUSTER, ENHANCED_CLUSTER) (example: ENHANCED_CLUSTER, x-obmcs-top-level-enum: #/definitions/ClusterType) |
vcnId | string | The OCID of the virtual cloud network (VCN) in which the cluster exists (example: ocid1.vcn.oc1.iad.aaaaaaaa5e3hn7hk6y63awlhbvlhsumkn5p3ficbjcevbnoylvptcpkxtsaa) |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | clusterId, region | opc-request-id, shouldIncludeOidcConfigFile | Get the details of a cluster. |
list | select | compartmentId, region | lifecycleState, name, limit, page, sortOrder, sortBy, opc-request-id | List all the cluster objects in a compartment. |
create | insert | region, name, compartmentId, vcnId, kubernetesVersion | opc-retry-token, opc-request-id | Create a new cluster. |
update | update | clusterId, region | if-match, opc-request-id | Update the details of a cluster. |
delete | delete | clusterId, region | if-match, opc-request-id | Delete a cluster. |
complete_credential_rotation | exec | clusterId, region | opc-retry-token, opc-request-id, if-match | Complete cluster credential rotation. Retire old credentials from kubernetes components. |
extend_endpoint_decommission_rollback_deadline | exec | clusterId, region, rollbackDeadlineDelay | opc-retry-token, opc-request-id, if-match | Extend the rollback deadline of public api endpoint decommission for a cluster.<br />The operation can only be performed within decommission rollback deadline.<br /> |
cluster_migrate_to_native_vcn | exec | clusterId, region, endpointConfig | if-match, opc-request-id | Initiates cluster migration to use native VCN. |
rollback_public_api_endpoint_decommission | exec | clusterId, region | opc-retry-token, opc-request-id, if-match | Rollback public api endpoint decommission for a cluster, legacy kubernetes endpoint will be brought back once the operation is completed. <br />The operation can only be performed within decommission rollback deadline.<br /> |
start_credential_rotation | exec | clusterId, region, autoCompletionDelayDuration | opc-retry-token, opc-request-id, if-match | Start cluster credential rotation by adding new credentials, old credentials will still work after this operation. |
start_public_api_endpoint_decommission | exec | clusterId, region | opc-retry-token, opc-request-id, if-match | Start public api endpoint decommission for a cluster, legacy kubernetes endpoint will no longer available after this operation. |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
clusterId | string | The OCID of the cluster. |
compartmentId | string | The OCID of the compartment. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
lifecycleState | array | A cluster lifecycle state to filter on. Can have multiple parameters of this name. For more information, see [Monitoring Clusters](/Content/ContEng/Tasks/contengmonitoringclusters.htm) |
limit | integer | For list pagination. The maximum number of results per page, or items to return in a paginated "List" call. 1 is the minimum, 1000 is the maximum. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). |
name | string | The name to filter on. |
opc-request-id | string | Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. |
opc-retry-token | string | A token you supply to uniquely identify the request and provide idempotency if the request is retried. Idempotency tokens expire after 24 hours. |
page | string | For list pagination. The value of the opc-next-page response header from the previous "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). |
shouldIncludeOidcConfigFile | boolean | Boolean value to determine if the OpenIdConnectAuth configuration file should be displayed for the provided cluster. |
sortBy | string | The optional field to sort the results by. |
sortOrder | string | The optional order in which to sort the results. |
SELECT examples​
- get
- list
Get the details of a cluster.
SELECT
id,
name,
availableKubernetesUpgrades,
clusterPodNetworkOptions,
compartmentId,
definedTags,
endpointConfig,
endpoints,
freeformTags,
imagePolicyConfig,
kmsKeyId,
kubernetesVersion,
lifecycleDetails,
lifecycleState,
metadata,
openIdConnectDiscoveryEndpoint,
openIdConnectDiscoveryKey,
options,
systemTags,
type,
vcnId
FROM oci.container_engine.clusters
WHERE clusterId = '{{ clusterId }}' -- required
AND region = '{{ region }}' -- required
AND opc-request-id = '{{ opc-request-id }}'
AND shouldIncludeOidcConfigFile = '{{ shouldIncludeOidcConfigFile }}'
;
List all the cluster objects in a compartment.
SELECT
id,
name,
availableKubernetesUpgrades,
clusterPodNetworkOptions,
compartmentId,
definedTags,
endpointConfig,
endpoints,
freeformTags,
imagePolicyConfig,
kubernetesVersion,
lifecycleDetails,
lifecycleState,
metadata,
options,
systemTags,
type,
vcnId
FROM oci.container_engine.clusters
WHERE compartmentId = '{{ compartmentId }}' -- required
AND region = '{{ region }}' -- required
AND lifecycleState = '{{ lifecycleState }}'
AND name = '{{ name }}'
AND limit = '{{ limit }}'
AND page = '{{ page }}'
AND sortOrder = '{{ sortOrder }}'
AND sortBy = '{{ sortBy }}'
AND opc-request-id = '{{ opc-request-id }}'
;
INSERT examples​
- create
- Manifest
Create a new cluster.
INSERT INTO oci.container_engine.clusters (
clusterPodNetworkOptions,
compartmentId,
definedTags,
endpointConfig,
freeformTags,
imagePolicyConfig,
kmsKeyId,
kubernetesVersion,
name,
options,
type,
vcnId,
region,
opc-retry-token,
opc-request-id
)
SELECT
'{{ clusterPodNetworkOptions }}',
'{{ compartmentId }}' /* required */,
'{{ definedTags }}',
'{{ endpointConfig }}',
'{{ freeformTags }}',
'{{ imagePolicyConfig }}',
'{{ kmsKeyId }}',
'{{ kubernetesVersion }}' /* required */,
'{{ name }}' /* required */,
'{{ options }}',
'{{ type }}',
'{{ vcnId }}' /* required */,
'{{ region }}',
'{{ opc-retry-token }}',
'{{ opc-request-id }}'
;
# Description fields are for documentation purposes
- name: clusters
props:
- name: region
value: "{{ region }}"
description: Required parameter for the clusters resource.
- name: clusterPodNetworkOptions
description: |
Available CNIs and network options for existing and new node pools of the cluster
value:
- cniType: "{{ cniType }}"
- name: compartmentId
value: "{{ compartmentId }}"
description: |
The OCID of the compartment in which to create the cluster.
- name: definedTags
value: "{{ definedTags }}"
description: |
Defined tags for this resource. Each key is predefined and scoped to a namespace.
For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm).
Example: `{"Operations": {"CostCenter": "42"}}`
- name: endpointConfig
description: |
The properties that define the network configuration for the Cluster endpoint.
value:
isPublicIpEnabled: {{ isPublicIpEnabled }}
nsgIds:
- "{{ nsgIds }}"
securityAttributes: "{{ securityAttributes }}"
subnetId: "{{ subnetId }}"
- name: freeformTags
value: "{{ freeformTags }}"
description: |
Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace.
For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm).
Example: `{"Department": "Finance"}`
- name: imagePolicyConfig
description: |
The properties that define a image verification policy.
value:
isPolicyEnabled: {{ isPolicyEnabled }}
keyDetails:
- kmsKeyId: "{{ kmsKeyId }}"
- name: kmsKeyId
value: "{{ kmsKeyId }}"
description: |
The OCID of the KMS key to be used as the master encryption key for Kubernetes secret encryption.
When used, `kubernetesVersion` must be at least `v1.13.0`.
- name: kubernetesVersion
value: "{{ kubernetesVersion }}"
description: |
The version of Kubernetes to install into the cluster masters.
- name: name
value: "{{ name }}"
description: |
The name of the cluster. Avoid entering confidential information.
- name: options
description: |
The properties that define extra options for a cluster.
value:
addOns:
isKubernetesDashboardEnabled: {{ isKubernetesDashboardEnabled }}
isTillerEnabled: {{ isTillerEnabled }}
admissionControllerOptions:
isPodSecurityPolicyEnabled: {{ isPodSecurityPolicyEnabled }}
ipFamilies:
- "{{ ipFamilies }}"
kubernetesNetworkConfig:
podsCidr: "{{ podsCidr }}"
servicesCidr: "{{ servicesCidr }}"
openIdConnectDiscovery:
isOpenIdConnectDiscoveryEnabled: {{ isOpenIdConnectDiscoveryEnabled }}
openIdConnectTokenAuthenticationConfig:
caCertificate: "{{ caCertificate }}"
clientId: "{{ clientId }}"
configurationFile: "{{ configurationFile }}"
groupsClaim: "{{ groupsClaim }}"
groupsPrefix: "{{ groupsPrefix }}"
isOpenIdConnectAuthEnabled: {{ isOpenIdConnectAuthEnabled }}
issuerUrl: "{{ issuerUrl }}"
requiredClaims:
- key: "{{ key }}"
value: "{{ value }}"
signingAlgorithms:
- "{{ signingAlgorithms }}"
usernameClaim: "{{ usernameClaim }}"
usernamePrefix: "{{ usernamePrefix }}"
persistentVolumeConfig:
definedTags: "{{ definedTags }}"
freeformTags: "{{ freeformTags }}"
serviceLbConfig:
backendNsgIds:
- "{{ backendNsgIds }}"
definedTags: "{{ definedTags }}"
freeformTags: "{{ freeformTags }}"
serviceLbSubnetIds:
- "{{ serviceLbSubnetIds }}"
- name: type
value: "{{ type }}"
description: |
Type of cluster
valid_values: ['BASIC_CLUSTER', 'ENHANCED_CLUSTER']
- name: vcnId
value: "{{ vcnId }}"
description: |
The OCID of the virtual cloud network (VCN) in which to create the cluster.
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token you supply to uniquely identify the request and provide idempotency if the request is retried. Idempotency tokens expire after 24 hours.
description: A token you supply to uniquely identify the request and provide idempotency if the request is retried. Idempotency tokens expire after 24 hours.
- name: opc-request-id
value: "{{ opc-request-id }}"
description: Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID.
description: Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID.
UPDATE examples​
- update
Update the details of a cluster.
UPDATE oci.container_engine.clusters
SET
definedTags = '{{ definedTags }}',
freeformTags = '{{ freeformTags }}',
imagePolicyConfig = '{{ imagePolicyConfig }}',
kubernetesVersion = '{{ kubernetesVersion }}',
name = '{{ name }}',
options = '{{ options }}',
type = '{{ type }}'
WHERE
clusterId = '{{ clusterId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
AND opc-request-id = '{{ opc-request-id}}';
DELETE examples​
- delete
Delete a cluster.
DELETE FROM oci.container_engine.clusters
WHERE clusterId = '{{ clusterId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
AND opc-request-id = '{{ opc-request-id }}'
;
Lifecycle Methods​
- complete_credential_rotation
- extend_endpoint_decommission_rollback_deadline
- cluster_migrate_to_native_vcn
- rollback_public_api_endpoint_decommission
- start_credential_rotation
- start_public_api_endpoint_decommission
Complete cluster credential rotation. Retire old credentials from kubernetes components.
EXEC oci.container_engine.clusters.complete_credential_rotation
@clusterId='{{ clusterId }}' --required,
@region='{{ region }}' --required,
@opc-retry-token='{{ opc-retry-token }}',
@opc-request-id='{{ opc-request-id }}',
@if-match='{{ if-match }}'
;
Extend the rollback deadline of public api endpoint decommission for a cluster.<br />The operation can only be performed within decommission rollback deadline.<br />
EXEC oci.container_engine.clusters.extend_endpoint_decommission_rollback_deadline
@clusterId='{{ clusterId }}' --required,
@region='{{ region }}' --required,
@opc-retry-token='{{ opc-retry-token }}',
@opc-request-id='{{ opc-request-id }}',
@if-match='{{ if-match }}'
@@json=
'{
"rollbackDeadlineDelay": "{{ rollbackDeadlineDelay }}"
}'
;
Initiates cluster migration to use native VCN.
EXEC oci.container_engine.clusters.cluster_migrate_to_native_vcn
@clusterId='{{ clusterId }}' --required,
@region='{{ region }}' --required,
@if-match='{{ if-match }}',
@opc-request-id='{{ opc-request-id }}'
@@json=
'{
"decommissionDelayDuration": "{{ decommissionDelayDuration }}",
"endpointConfig": "{{ endpointConfig }}"
}'
;
Rollback public api endpoint decommission for a cluster, legacy kubernetes endpoint will be brought back once the operation is completed. <br />The operation can only be performed within decommission rollback deadline.<br />
EXEC oci.container_engine.clusters.rollback_public_api_endpoint_decommission
@clusterId='{{ clusterId }}' --required,
@region='{{ region }}' --required,
@opc-retry-token='{{ opc-retry-token }}',
@opc-request-id='{{ opc-request-id }}',
@if-match='{{ if-match }}'
;
Start cluster credential rotation by adding new credentials, old credentials will still work after this operation.
EXEC oci.container_engine.clusters.start_credential_rotation
@clusterId='{{ clusterId }}' --required,
@region='{{ region }}' --required,
@opc-retry-token='{{ opc-retry-token }}',
@opc-request-id='{{ opc-request-id }}',
@if-match='{{ if-match }}'
@@json=
'{
"autoCompletionDelayDuration": "{{ autoCompletionDelayDuration }}"
}'
;
Start public api endpoint decommission for a cluster, legacy kubernetes endpoint will no longer available after this operation.
EXEC oci.container_engine.clusters.start_public_api_endpoint_decommission
@clusterId='{{ clusterId }}' --required,
@region='{{ region }}' --required,
@opc-retry-token='{{ opc-retry-token }}',
@opc-request-id='{{ opc-request-id }}',
@if-match='{{ if-match }}'
;