EKS

Amazon EKS (eks) on fakecloud: complete 70-op Elastic Kubernetes Service control plane — clusters, node groups, Fargate profiles, add-ons, access entries, identity-provider configs, pod identity, insights, capabilities, certificate authorities, and EKS Anywhere. restJson1.

fakecloud implements Amazon EKS (eks), the managed Kubernetes service, as a restJson1 control plane. The complete 70-operation surface ships — clusters, managed node groups, Fargate profiles, add-ons, access entries, OIDC identity-provider configs, pod-identity associations, upgrade insights, capabilities, cluster certificate authorities, connected-cluster registration, encryption config, and EKS Anywhere subscriptions — backed by account-partitioned state that persists across restarts in persistent mode.

Supported now (all 70 operations)

  • Cluster lifecycle — CreateCluster, DescribeCluster, ListClusters, DeleteCluster. Clusters are created with the requested roleArn, resourcesVpcConfig, version (default 1.34), and tags, and transition CREATING -> ACTIVE on describe (deterministic, no background timer). Like EKS, CreateCluster (and AWS::EKS::Cluster) creates the cluster security group in EC2, in the VPC of the cluster's subnets: named eks-cluster-sg-<cluster>-<id>, tagged aws:eks:cluster-name and kubernetes.io/cluster/<cluster>=owned, with a self-referencing all-traffic ingress rule and an all-traffic egress rule. resourcesVpcConfig returns it as clusterSecurityGroupId (with the subnets' vpcId), it can be described, tagged and given rules through EC2, and DeleteCluster deletes it.
  • Cluster updates — UpdateClusterConfig, UpdateClusterVersion, each minting a tracked Update that settles InProgress -> Successful on describe; DescribeUpdate and ListUpdates return the update history.
  • Managed node groups — CreateNodegroup, DescribeNodegroup, ListNodegroups, DeleteNodegroup, plus UpdateNodegroupConfig and UpdateNodegroupVersion (tracked updates). Node groups carry nodeRole, subnets, scalingConfig, and transition CREATING -> ACTIVE on describe. Like EKS, each node group runs as a real EC2 Auto Scaling group (resources.autoScalingGroups), tagged eks:cluster-name, eks:nodegroup-name and the cluster-autoscaler discovery tags, with zones from the node group's subnets: it can be described and tagged through Auto Scaling, follows UpdateNodegroupConfig scaling changes, and is deleted with the node group. UpdateNodegroupVersion applies a launchTemplate version (the template's id / name must match the node group's).
  • Fargate profiles — CreateFargateProfile, DescribeFargateProfile, ListFargateProfiles, DeleteFargateProfile with podExecutionRoleArn and selectors, their own CREATING -> ACTIVE transition.
  • Add-ons — CreateAddon, DescribeAddon, ListAddons, DeleteAddon, UpdateAddon (tracked version updates), plus the read-only catalogue ops DescribeAddonVersions and DescribeAddonConfiguration. The catalogue is a snapshot of the real describe-addon-versions output from 2025-11-25 (the same date as the cluster-version table): every AWS-owned add-on (vpc-cni, coredns, kube-proxy, the EBS/EFS/FSx/Mountpoint for S3 CSI drivers, snapshot-controller, eks-pod-identity-agent, aws-guardduty-agent, aws-secrets-store-csi-driver-provider, aws-privateca-connector-for-kubernetes, amazon-cloudwatch-observability, adot, eks-node-monitoring-agent, aws-network-flow-monitoring-agent, sriov-network-metrics-exporter and the SageMaker HyperPod and Spaces add-ons) and every EKS-published community add-on (metrics-server, kube-state-metrics, prometheus-node-exporter, cert-manager, external-dns, fluent-bit), plus the 40 AWS Marketplace listings offered for 1.28-1.34 (with marketplaceInformation; Marketplace subscriptions are not modeled, so they install), with AWS's version strings, architectures, compute types, and per-Kubernetes-version compatibilities flagging the default version. kubernetesVersion, addonName, types, owners, and publishers filter it, and CreateAddon (or an AWS::EKS::Addon without AddonVersion) installs the default for the cluster's version. An add-on with no build for the cluster's Kubernetes version, or an unknown add-on name, is refused with InvalidParameterException ("Addon specified is not supported in kubernetes version", checked before any requested version); an addonVersion not offered for the cluster's version, on create or update, is refused with "Addon version specified is not supported". Messages match a live EKS cluster. DescribeAddonConfiguration recommends the documented pod identity service account and managed policies (for example external-dns -> AmazonRoute53FullAccess). An add-on's podIdentityAssociations become real pod identity associations in the add-on's namespace, owned by the add-on (ownerArn): they resolve through DescribePodIdentityAssociation, an UpdateAddon keeps the association (and ARN) of a service account that stays, and DeleteAddon deletes them.
  • Access entries — CreateAccessEntry, DescribeAccessEntry, ListAccessEntries, DeleteAccessEntry, UpdateAccessEntry, plus AssociateAccessPolicy, DisassociateAccessPolicy, ListAssociatedAccessPolicies (cluster/namespace accessScope), and the read-only ListAccessPolicies catalogue of the AmazonEKS* cluster-access policies.
  • OIDC identity-provider configs — AssociateIdentityProviderConfig and DisassociateIdentityProviderConfig (each minting a tracked cluster Update), DescribeIdentityProviderConfig, ListIdentityProviderConfigs.
  • Pod-identity associations — CreatePodIdentityAssociation, DescribePodIdentityAssociation, ListPodIdentityAssociations, UpdatePodIdentityAssociation, DeletePodIdentityAssociation (map a namespace/serviceAccount to a roleArn, a--prefixed associationId).
  • Upgrade insights — ListInsights, DescribeInsight (seeded PASSING UPGRADE_READINESS findings per cluster), StartInsightsRefresh, DescribeInsightsRefresh.
  • Capabilities — CreateCapability, DescribeCapability, ListCapabilities, UpdateCapability (tracked Update), DeleteCapability.
  • Certificate authorities — CreateCertificateAuthority, DescribeCertificateAuthority, ListCertificateAuthorities, DeleteCertificateAuthority, ActivateCertificateAuthority. Every cluster is created with an EKS-signed CA already IN_USE; a customer-created CA starts NOT_USED/IN_PROGRESS, settles to COMPLETE on describe, and activation promotes it while demoting the previous signer to NOT_USED with rollbackAvailable. Deleting the signing CA is refused with ResourceInUseException.
  • Connected clusters — RegisterCluster (creates a PENDING cluster with a connectorConfig) and DeregisterCluster.
  • Cluster maintenance — AssociateEncryptionConfig and CancelUpdate (both operate on tracked Update records), plus the read-only DescribeClusterVersions catalogue (Kubernetes 1.28-1.34 as of 2025-11-25, with patch and platform versions, AWS's release and standard/extended support dates, and each version's support status on that date).
  • EKS Anywhere subscriptions — CreateEksAnywhereSubscription, DescribeEksAnywhereSubscription, ListEksAnywhereSubscriptions, UpdateEksAnywhereSubscription, DeleteEksAnywhereSubscription (account-scoped, term/licenseQuantity/autoRenew).
  • Tagging — TagResource, UntagResource, ListTagsForResource (EKS uses a map<String,String> tag shape, keyed by resource ARN).
  • 100% conformance across the full surface: all 1,995 generated Smithy probe variants for the 70 operations pass. There is no real Kubernetes API-server endpoint; the control plane models the AWS management API, not kubectl traffic.

    Example

    import boto3
    eks = boto3.client("eks", endpoint_url="http://localhost:4566")
    
    eks.create_cluster(
        name="app",
        roleArn="arn:aws:iam::123456789012:role/eksClusterRole",
        resourcesVpcConfig={"subnetIds": ["subnet-1", "subnet-2"]},
        version="1.31",
    )
    
    cluster = eks.describe_cluster(name="app")["cluster"]
    print(cluster["status"], cluster["version"])  # ACTIVE 1.31