eksctl, Run To Its First AWS Call
eksctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which runs eksctl get cluster with no credentials and expects it to stop at 'get credentials'. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-20 · podman 4.9.3 · ansible 2.21.4 · how we verify
Documentation
eksctl
eksctl eksctl on EL 10 from the vendor's release, checked against the
published SHA-256, pinned to a version, installed as root's binary
in /usr/local/bin. Original role for EL 10, live-tested with podman on
Rocky Linux 10.
No package worth the name. EL 10 carries no eksctl, and a
third-party repository is one more key to trust. This role takes the
release from eksctl.io, has Ansible's get_url refuse the asset unless
its SHA-256 is the published one, and the live test checks the asset on
disk against the same published value again.
Pinned. eksctl_version is what gets installed, kept in a directory
of its own so the checksum file and the asset it names stay together. A
newer release is a variable change and a run; the same version is
changed=0.
Proven to run. The live test runs eksctl get cluster --region eu-north-1 and expects
"get credentials" - the binary ran all the way to the point where it
needed something this host does not have.
Run to its first AWS call. eksctl get cluster with no
credentials stops at "get credentials" (no profile, no environment, no
instance role), which is the point where it would ask STS who it is;
the live test expects exactly that. Credentials are the AWS CLI's (a
profile, environment variables or an instance role), the same ones the
aws-cli-v2 role in this catalogue documents. The asset is named
Linux_amd64 / Linux_arm64 with a capital L.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test