View a markdown version of this page

EksAccessEntry - Amazon Batch
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

EksAccessEntry

Configures whether Amazon Batch manages an Amazon EKS access entry on the cluster for the compute environment. For information on how the fields interact with the cluster's authenticationMode and with other compute environments that share the cluster, see Amazon EKS access entry authentication in the Amazon Batch User Guide.

Note

Setting desiredState=ENABLED on a single compute environment does not guarantee that Amazon Batch creates an access entry, and setting desiredState=DISABLED on a single compute environment does not guarantee that Amazon Batch deletes one. Amazon Batch compares the desiredState across all compute environments that target the same cluster. The Amazon Batch-managed access entry is created only when all compute environments have desiredState=ENABLED, and deleted only when all have desiredState=DISABLED. If you have multiple compute environments on the same cluster, set desiredState consistently across all of them to avoid uncertainty. For more information, see Reconciling desiredState across compute environments in the Amazon Batch User Guide.

Contents

desiredState

The desired access entry state for the compute environment. Valid values:

ENABLED

Amazon Batch manages an access entry on the cluster for the compute environment.

DISABLED

Amazon Batch deletes the Amazon Batch-managed access entry for the cluster. This value is rejected if the cluster's authenticationMode is API, because such a cluster doesn't support the aws-auth ConfigMap.

INHERIT_FROM_CLUSTER

Amazon Batch defers to the cluster's current access entry status. On a cluster whose authentication mode is API, Amazon Batch creates and manages an access entry. On a cluster whose authentication mode is API_AND_CONFIG_MAP or CONFIG_MAP, Amazon Batch neither adds nor removes an access entry.

Type: String

Valid Values: ENABLED | DISABLED | INHERIT_FROM_CLUSTER

Required: Yes

status

The observed state of the access entry on the cluster. ACTIVE means that an access entry for the compute environment exists on the cluster and takes precedence over the aws-auth ConfigMap. INACTIVE means that no Amazon Batch-managed access entry is present. This is a read-only field returned by DescribeComputeEnvironments.

Type: String

Valid Values: ACTIVE | INACTIVE

Required: No

See Also

For more information about using this API in one of the language-specific Amazon SDKs, see the following: