This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::Batch::ComputeEnvironment EksAccessEntry
Configures whether AWS Batch manages an Amazon EKS access entry on the cluster for the compute
environment. For information on how the fields interact with the cluster's
authenticationMode and with other compute environments that share the cluster,
see Amazon EKS access entry
authentication in the AWS Batch User Guide.
Note
Setting desiredState=ENABLED on a single compute environment does not guarantee that AWS Batch creates an access
entry, and setting desiredState=DISABLED on a single compute environment does not guarantee that AWS Batch deletes
one. AWS Batch compares the desiredState across all compute environments that
target the same cluster. The AWS Batch-managed access entry is created only when all compute environments have
desiredState=ENABLED, and deleted only when all have
desiredState=DISABLED. If you have multiple compute environments on the same
cluster, set desiredState consistently across all of them to avoid uncertainty.
For more information, see Reconciling
desiredState across compute environments in the
AWS Batch User Guide.
Syntax
To declare this entity in your CloudFormation template, use the following syntax:
JSON
{ "DesiredState" :String, "Status" :String}
YAML
DesiredState:StringStatus:String
Properties
DesiredState-
The desired access entry state for the compute environment. Valid values:
- ENABLED
-
AWS Batch manages an access entry on the cluster for the compute environment.
- DISABLED
-
AWS Batch deletes the AWS Batch-managed access entry for the cluster. This value is rejected if the cluster's
authenticationModeisAPI, because such a cluster doesn't support theaws-authConfigMap. - INHERIT_FROM_CLUSTER
-
AWS Batch defers to the cluster's current access entry
status. On a cluster whose authentication mode isAPI, AWS Batch creates and manages an access entry. On a cluster whose authentication mode isAPI_AND_CONFIG_MAPorCONFIG_MAP, AWS Batch neither adds nor removes an access entry.
Required: No
Type: String
Allowed values:
ENABLED | DISABLED | INHERIT_FROM_CLUSTERUpdate requires: No interruption
Status-
The observed state of the access entry on the cluster.
ACTIVEmeans that an access entry for the compute environment exists on the cluster and takes precedence over theaws-authConfigMap.INACTIVEmeans that no AWS Batch-managed access entry is present. This is a read-only field returned byDescribeComputeEnvironments.Required: No
Type: String
Allowed values:
ACTIVE | INACTIVEUpdate requires: No interruption