DEV Community

Ravindu Fernando
Ravindu Fernando

Posted on

A Production Ready EKS Deployment with IaC & GitOps - Part 2 - Configuring Terraform Backend & Validate Prerequisites

Refer here for corresponding Git commit: Provision Terraform Backend


Throughout this guide, all infrastructure and applications will either be named or prefixed with "opsninja" for easy identification. Our deployments will take place in the us-east-1 region.

Before we start deploying our AWS EKS cluster using Terraform, we need to ensure that the required tools are installed and properly configured.

1. Install AWS CLI v2

The AWS CLI (Command Line Interface) v2 is required to interact with AWS services. To install it, follow these steps:

For macOS

brew install awscli
Enter fullscreen mode Exit fullscreen mode

For Linux

curl "" -o ""
sudo ./aws/install
Enter fullscreen mode Exit fullscreen mode

For Windows

  1. Download the installer from the official AWS website: AWS CLI v2
  2. Run the installer and follow the setup instructions.
  3. Verify the installation:
   aws --version
Enter fullscreen mode Exit fullscreen mode

You should see an output similar to:

   aws-cli/2.x.x Python/x.x.x Linux/x86_64
Enter fullscreen mode Exit fullscreen mode

2. Install Helm (Kubernetes Package Manager)

Helm is a package manager for Kubernetes that simplifies the deployment of applications and services.

For macOS

brew install helm
Enter fullscreen mode Exit fullscreen mode

For Linux

curl | bash
Enter fullscreen mode Exit fullscreen mode

For Windows (using Chocolatey)

choco install kubernetes-helm
Enter fullscreen mode Exit fullscreen mode

Verify the installation:

helm version
Enter fullscreen mode Exit fullscreen mode

You should see an output similar to:

version.BuildInfo{Version:"v3.x.x", GitCommit:"xxxx", GoVersion:"go1.x.x"}
Enter fullscreen mode Exit fullscreen mode

3. Install AWS IAM Authenticator

The AWS IAM Authenticator is required for authentication with the Amazon EKS cluster.

For macOS

brew install aws-iam-authenticator
Enter fullscreen mode Exit fullscreen mode

For Linux

curl -o aws-iam-authenticator
chmod +x ./aws-iam-authenticator
mv ./aws-iam-authenticator /usr/local/bin/
Enter fullscreen mode Exit fullscreen mode

For Windows

Download the binary from the official AWS EKS release and add it to your system's PATH.

Verify the installation:

aws-iam-authenticator version
Enter fullscreen mode Exit fullscreen mode

Expected output:

Enter fullscreen mode Exit fullscreen mode

4. Configure AWS CLI with a Profile Named terraform

We will be using a dedicated AWS CLI profile called terraform to provision our infrastructure with Terraform.

Run the following command to configure AWS CLI with the terraform profile:

aws configure --profile terraform
Enter fullscreen mode Exit fullscreen mode

You'll be prompted to enter your AWS credentials:

AWS Access Key ID [None]: <YOUR_ACCESS_KEY>
AWS Secret Access Key [None]: <YOUR_SECRET_KEY>
Default region name [None]: us-east-1
Default output format [None]: json
Enter fullscreen mode Exit fullscreen mode

Verify the Profile

To check if the profile is configured correctly, run:

aws configure list --profile terraform
Enter fullscreen mode Exit fullscreen mode

or list all available profiles:

aws configure list-profiles
Enter fullscreen mode Exit fullscreen mode

This profile will be used throughout this guide to authenticate and interact with AWS when deploying infrastructure using Terraform.

5. Validate AWS Configuration

To confirm that the AWS CLI and profile are correctly set up, run:

aws sts get-caller-identity --profile terraform
Enter fullscreen mode Exit fullscreen mode

This should return details of the authenticated IAM user or role.

With AWS CLI, Helm, and AWS IAM Authenticator installed and the terraform profile configured, we are now ready to proceed with configuring the Terraform backend

Configuring the Terraform Backend

Throughout this guide, all infrastructure and applications will either be named or prefixed with "opsninja" for easy identification. Our deployments will take place in the us-east-1 region.

For better state management, we will configure a Terraform backend using AWS S3 and DynamoDB. This will allow us to store our Terraform state remotely and enable state locking to prevent conflicts in collaborative environments.

Terraform Backend Configuration (

Below is the Terraform backend configuration, which uses an S3 bucket for state storage and a DynamoDB table for state locking.

provider "aws" {
  region = var.region
  profile = "terraform"

resource "aws_s3_bucket" "terraform_state_bucket" {
  bucket = var.s3_bucket_name

  versioning {
    enabled = true

  server_side_encryption_configuration {
    rule {
      apply_server_side_encryption_by_default {
        sse_algorithm = "AES256"

  lifecycle {
    prevent_destroy = true

  tags = {
    Name        = var.s3_bucket_name
    Environment = var.environment
    App         =
    ManagedBy   = "Terraform"

resource "aws_dynamodb_table" "terraform_lock_table" {
  name         = var.dynamodb_table_name
  billing_mode = "PAY_PER_REQUEST"
  hash_key     = "LockID"

  attribute {
    name = "LockID"
    type = "S"

  tags = {
    Name        = var.dynamodb_table_name
    Environment = var.environment
    App         =
    ManagedBy   = "Terraform"

Enter fullscreen mode Exit fullscreen mode

Terraform Variables (

variable "app" {
  description = "App Name"
  type        = string
  default     = "opsninja"

variable "region" {
  description = "AWS region"
  type        = string
  default     = "us-east-1"

variable "s3_bucket_name" {
  description = "The name of the S3 bucket for storing Terraform state"
  type        = string
  default     = "opsninja-tf-state-prod"

variable "dynamodb_table_name" {
  description = "The name of the DynamoDB table for state locking"
  type        = string
  default     = "opsninja-tf-state-prod"

variable "environment" {
  description = "Environment for tagging purposes (e.g., dev, prod)"
  type        = string
  default     = "prod"

Enter fullscreen mode Exit fullscreen mode

Terraform Output (

output "s3_bucket_name" {
  value = aws_s3_bucket.terraform_state_bucket.bucket

output "dynamodb_table_name" {
  value =

Enter fullscreen mode Exit fullscreen mode

Deploying the Terraform Backend

Once the backend is defined, apply Terraform using the following command:

terraform init
terraform apply
Enter fullscreen mode Exit fullscreen mode

Deployment Output and State Management

Once the deployment is complete, the output will display the S3 bucket and DynamoDB table that were created. Make sure to note these values, as they will be required for future steps in this guide.

Additionally, the state file for backend provisioning is saved locally. This file must be preserved, as it is necessary to manage the lifecycle of the S3 bucket and DynamoDB table in the future.

Top comments (0)