AWS EC2

The current AMIs for all Flatcar Container Linux channels and EC2 regions are listed below and updated frequently. Using CloudFormation is the easiest way to launch a cluster, but it is also possible to follow the manual steps at the end of the article. Questions can be directed to the Flatcar Container Linux Discord server or user mailing list .

At the end of the document there are instructions for deploying with Terraform.

Release retention time

After publishing, releases will remain available as public AMIs on AWS for 9 months. AMIs older than 9 months will be un-published in regular garbage collection sweeps. Please note that this will not impact existing AWS instances that use those releases. However, deploying new instances (e.g. in autoscaling groups pinned to a specific AMI) will not be possible after the AMI was un-published.

Choosing a channel

Flatcar Container Linux is designed to be updated automatically with different schedules per channel. You can disable this feature , although we don’t recommend it. Read the release notes for specific features and bug fixes.

The Stable channel should be used by production clusters. Versions of Flatcar Container Linux are battle-tested within the Beta and Alpha channels before being promoted. The current version is Flatcar Container Linux 4593.2.4.

View as json feed: amd64 arm64
EC2 Region AMI Type AMI ID CloudFormation
af-south-1 HVM (amd64) ami-08b6dfc0b6151f668 Launch Stack
HVM (arm64) ami-0ccf16e1ef102f205 Launch Stack
ap-east-1 HVM (amd64) ami-097e8002f5a08d4ae Launch Stack
HVM (arm64) ami-008694a8c8a2d53b4 Launch Stack
ap-northeast-1 HVM (amd64) ami-06ec3b69afe18653d Launch Stack
HVM (arm64) ami-0db38f9ac13358835 Launch Stack
ap-northeast-2 HVM (amd64) ami-04f1e1b18b8836033 Launch Stack
HVM (arm64) ami-09984438521ec45a9 Launch Stack
ap-south-1 HVM (amd64) ami-0f8333823246e0b89 Launch Stack
HVM (arm64) ami-071e9c57242b51741 Launch Stack
ap-southeast-1 HVM (amd64) ami-0bf32a12feef85c0b Launch Stack
HVM (arm64) ami-02362446f54c42e69 Launch Stack
ap-southeast-2 HVM (amd64) ami-0a9429d40c7f6dc2b Launch Stack
HVM (arm64) ami-07b177c83be13e1d2 Launch Stack
ap-southeast-3 HVM (amd64) ami-0f5958d3b51f35acd Launch Stack
HVM (arm64) ami-0d7c303bc880b5672 Launch Stack
ca-central-1 HVM (amd64) ami-025555f13cd27f8ec Launch Stack
HVM (arm64) ami-003578b8afdbf0afa Launch Stack
eu-central-1 HVM (amd64) ami-060eff4bc38a40d0f Launch Stack
HVM (arm64) ami-0e2f02031b2d7ee8e Launch Stack
eu-north-1 HVM (amd64) ami-08cdaa09a2fa03b39 Launch Stack
HVM (arm64) ami-0b0c5b8e2fb0001ba Launch Stack
eu-south-1 HVM (amd64) ami-04539dce2b2f56d13 Launch Stack
HVM (arm64) ami-0cb9ee147fdab6ea7 Launch Stack
eu-west-1 HVM (amd64) ami-03686afba70a90143 Launch Stack
HVM (arm64) ami-0dc179326fcc1d0da Launch Stack
eu-west-2 HVM (amd64) ami-0091ec1940064594e Launch Stack
HVM (arm64) ami-04b470f589b29819a Launch Stack
eu-west-3 HVM (amd64) ami-0cc6fbf04c0d7cf71 Launch Stack
HVM (arm64) ami-0e52392d70abb42a2 Launch Stack
sa-east-1 HVM (amd64) ami-0b8144b41084ef6a1 Launch Stack
HVM (arm64) ami-0dae952de3f4dfcd9 Launch Stack
us-east-1 HVM (amd64) ami-013922581faeb0980 Launch Stack
HVM (arm64) ami-03a6c33c0e834a343 Launch Stack
us-east-2 HVM (amd64) ami-001716aede1c049d7 Launch Stack
HVM (arm64) ami-04b3f1839fdee916b Launch Stack
us-west-1 HVM (amd64) ami-0197b8ecd6a086070 Launch Stack
HVM (arm64) ami-03a8f8992b2dd1ffe Launch Stack
us-west-2 HVM (amd64) ami-0cbef90be4140a3d9 Launch Stack
HVM (arm64) ami-00a71c218b07fab44 Launch Stack

The Beta channel consists of promoted Alpha releases. The current version is Flatcar Container Linux 4722.1.0.

View as json feed: amd64 arm64
EC2 Region AMI Type AMI ID CloudFormation
af-south-1 HVM (amd64) ami-01e6749289a3009df Launch Stack
HVM (arm64) ami-0fe4009e464e227d0 Launch Stack
ap-east-1 HVM (amd64) ami-0350aae2b9a6670e8 Launch Stack
HVM (arm64) ami-004adad1d66a34d61 Launch Stack
ap-northeast-1 HVM (amd64) ami-0e30d94493687e560 Launch Stack
HVM (arm64) ami-0598b962a9d5e8f57 Launch Stack
ap-northeast-2 HVM (amd64) ami-00cc0c33307c5b0ff Launch Stack
HVM (arm64) ami-0e442454da232a64e Launch Stack
ap-south-1 HVM (amd64) ami-060cee9a54952ae50 Launch Stack
HVM (arm64) ami-0ab896af06097264d Launch Stack
ap-southeast-1 HVM (amd64) ami-087c56b9eb5acb7dc Launch Stack
HVM (arm64) ami-07721ae0f8e4c2609 Launch Stack
ap-southeast-2 HVM (amd64) ami-036fd74a4d7f3bc36 Launch Stack
HVM (arm64) ami-0baf147a09ccf7601 Launch Stack
ap-southeast-3 HVM (amd64) ami-063d750ec6cf65622 Launch Stack
HVM (arm64) ami-08a24588e60e51cd6 Launch Stack
ca-central-1 HVM (amd64) ami-06e0b936568d3f6cd Launch Stack
HVM (arm64) ami-033ccbff08974fc09 Launch Stack
eu-central-1 HVM (amd64) ami-0066585827f472d11 Launch Stack
HVM (arm64) ami-0f45b1ea9a440eb46 Launch Stack
eu-north-1 HVM (amd64) ami-0ec64551135ac7e9e Launch Stack
HVM (arm64) ami-04f37ecfbb65dadff Launch Stack
eu-south-1 HVM (amd64) ami-081643abd7f79a26f Launch Stack
HVM (arm64) ami-075508d990127e50f Launch Stack
eu-west-1 HVM (amd64) ami-0c7446391b9744a47 Launch Stack
HVM (arm64) ami-04c51bddaff6e4f7e Launch Stack
eu-west-2 HVM (amd64) ami-07697f8e25507a0c7 Launch Stack
HVM (arm64) ami-0bfbe25d81b179d75 Launch Stack
eu-west-3 HVM (amd64) ami-0fcd5e081e6aed716 Launch Stack
HVM (arm64) ami-0a577c9ed5d92dd04 Launch Stack
sa-east-1 HVM (amd64) ami-0ab61fff9730c08cf Launch Stack
HVM (arm64) ami-0c4070719ea49dece Launch Stack
us-east-1 HVM (amd64) ami-090c7530884351c27 Launch Stack
HVM (arm64) ami-0c752a441b40786e8 Launch Stack
us-east-2 HVM (amd64) ami-06dd41b6ee655dd0f Launch Stack
HVM (arm64) ami-0899c3a1848fc1f79 Launch Stack
us-west-1 HVM (amd64) ami-0f1c7e8d32c417120 Launch Stack
HVM (arm64) ami-09e6ae0e0caf3ca40 Launch Stack
us-west-2 HVM (amd64) ami-06eff5083109fcaab Launch Stack
HVM (arm64) ami-0e1c4836bc6e0f862 Launch Stack

The Alpha channel closely tracks master and is released frequently. The newest versions of system libraries and utilities will be available for testing. The current version is Flatcar Container Linux 4757.0.0.

View as json feed: amd64 arm64
EC2 Region AMI Type AMI ID CloudFormation
af-south-1 HVM (amd64) ami-0f72c882256d29b8d Launch Stack
HVM (arm64) ami-00d54e384fc8174bd Launch Stack
ap-east-1 HVM (amd64) ami-0b62d82dfb00700c1 Launch Stack
HVM (arm64) ami-0290df81d00e06321 Launch Stack
ap-northeast-1 HVM (amd64) ami-0f03aaf5ccc0fa059 Launch Stack
HVM (arm64) ami-0e5d8cb089c8fa108 Launch Stack
ap-northeast-2 HVM (amd64) ami-055c6c9bc789c5436 Launch Stack
HVM (arm64) ami-07b5d4ce6e493ed8f Launch Stack
ap-south-1 HVM (amd64) ami-0dc5f0554f58bf71d Launch Stack
HVM (arm64) ami-0ff96767f6043b948 Launch Stack
ap-southeast-1 HVM (amd64) ami-0f1bc2a0751fa4b9e Launch Stack
HVM (arm64) ami-07d0d3efd3aca40d7 Launch Stack
ap-southeast-2 HVM (amd64) ami-03eee961782414b46 Launch Stack
HVM (arm64) ami-08e6b9bfc8d4adfa1 Launch Stack
ap-southeast-3 HVM (amd64) ami-09a5e846d08797bd4 Launch Stack
HVM (arm64) ami-0e6140810fb35dd6e Launch Stack
ca-central-1 HVM (amd64) ami-036f99504b21558ba Launch Stack
HVM (arm64) ami-0d518d2c4ab130aa1 Launch Stack
eu-central-1 HVM (amd64) ami-059396c4ae331979f Launch Stack
HVM (arm64) ami-01ba6c5b91fc112b4 Launch Stack
eu-north-1 HVM (amd64) ami-0c1830c6859577af2 Launch Stack
HVM (arm64) ami-0e5ad1a6a75a694f7 Launch Stack
eu-south-1 HVM (amd64) ami-0202a2c3bd9dc4d7d Launch Stack
HVM (arm64) ami-08c22395b159ea60a Launch Stack
eu-west-1 HVM (amd64) ami-01fd141494ee39849 Launch Stack
HVM (arm64) ami-06e0976e22ae6d8df Launch Stack
eu-west-2 HVM (amd64) ami-02002dce25ee5563b Launch Stack
HVM (arm64) ami-0ec5a432e8f3db5d9 Launch Stack
eu-west-3 HVM (amd64) ami-0d3938416083da297 Launch Stack
HVM (arm64) ami-0ebf2897cc6344f75 Launch Stack
sa-east-1 HVM (amd64) ami-021433fe791ae8a6d Launch Stack
HVM (arm64) ami-0fcaedcc2d259e9a8 Launch Stack
us-east-1 HVM (amd64) ami-04a78cf36bbf49fdd Launch Stack
HVM (arm64) ami-01df5eb388e1dabb6 Launch Stack
us-east-2 HVM (amd64) ami-01531cbeabda86891 Launch Stack
HVM (arm64) ami-02e4a9966853c14b7 Launch Stack
us-west-1 HVM (amd64) ami-0118e2cd4cc40e816 Launch Stack
HVM (arm64) ami-08e7444caaa087a38 Launch Stack
us-west-2 HVM (amd64) ami-054c35a1d4474bd51 Launch Stack
HVM (arm64) ami-0d2cf4db892565542 Launch Stack

LTS release streams are maintained for an extended lifetime of 18 months. The yearly LTS streams have an overlap of 6 months. The current version is Flatcar Container Linux 4081.3.9.

View as json feed: amd64 arm64
EC2 Region AMI Type AMI ID CloudFormation
af-south-1 HVM (amd64) ami-0b904e5dada5bc89a Launch Stack
HVM (arm64) ami-090164283d339d74a Launch Stack
ap-east-1 HVM (amd64) ami-0b5b36ac1be2968c5 Launch Stack
HVM (arm64) ami-0fd256fac1a35b6fc Launch Stack
ap-northeast-1 HVM (amd64) ami-068f67a5a1b9674b9 Launch Stack
HVM (arm64) ami-0bb9796ea9c6575b1 Launch Stack
ap-northeast-2 HVM (amd64) ami-084ac86ad25877b5a Launch Stack
HVM (arm64) ami-0aaf13ba38a3a267f Launch Stack
ap-south-1 HVM (amd64) ami-031aa5d62922b5674 Launch Stack
HVM (arm64) ami-054a3c9b47029239a Launch Stack
ap-southeast-1 HVM (amd64) ami-01d0051fcce4a9892 Launch Stack
HVM (arm64) ami-0bf56f81b88c9e5cb Launch Stack
ap-southeast-2 HVM (amd64) ami-048e2314285694c14 Launch Stack
HVM (arm64) ami-0c382d7001580d3ba Launch Stack
ap-southeast-3 HVM (amd64) ami-041f1a0fd946f954c Launch Stack
HVM (arm64) ami-096e0c8974edcc14d Launch Stack
ca-central-1 HVM (amd64) ami-03c25c564471f41e2 Launch Stack
HVM (arm64) ami-0c220f7b6a31f3a64 Launch Stack
eu-central-1 HVM (amd64) ami-0c4c3da0be4353991 Launch Stack
HVM (arm64) ami-0be8271b3e5d3803a Launch Stack
eu-north-1 HVM (amd64) ami-00622e23044fb59e5 Launch Stack
HVM (arm64) ami-0e309a238e718d1bb Launch Stack
eu-south-1 HVM (amd64) ami-0bdeb26109d534b66 Launch Stack
HVM (arm64) ami-04c4204e36a96274d Launch Stack
eu-west-1 HVM (amd64) ami-03596e46ca171f3ed Launch Stack
HVM (arm64) ami-0189238ed8d89585a Launch Stack
eu-west-2 HVM (amd64) ami-09febbaada6753079 Launch Stack
HVM (arm64) ami-007ebb9e5b321b6d5 Launch Stack
eu-west-3 HVM (amd64) ami-0825d7994556da492 Launch Stack
HVM (arm64) ami-077c7f73bc167766e Launch Stack
sa-east-1 HVM (amd64) ami-07650baec102eb941 Launch Stack
HVM (arm64) ami-0e7d94a8d1b0f63d2 Launch Stack
us-east-1 HVM (amd64) ami-0af452695f2177ae4 Launch Stack
HVM (arm64) ami-03cabebb82aeab5f5 Launch Stack
us-east-2 HVM (amd64) ami-00d36ce318d645925 Launch Stack
HVM (arm64) ami-0bdf77a43e365d718 Launch Stack
us-west-1 HVM (amd64) ami-04a3bb2e99cf59a9d Launch Stack
HVM (arm64) ami-0fbf635e7791a69a0 Launch Stack
us-west-2 HVM (amd64) ami-026323f0e8ceded3b Launch Stack
HVM (arm64) ami-0ef2dabf78a4080bf Launch Stack

Butane Configs

Flatcar Container Linux allows you to configure machine parameters, configure networking, launch systemd units on startup, and more via Butane Configs. These configs are then transpiled into Ignition configs and given to booting machines. Head over to the docs to learn about the supported features .

You can provide a raw Ignition JSON config to Flatcar Container Linux via the Amazon web console or via the EC2 API .

As an example, this Butane YAML config will start an NGINX Docker container:

variant: flatcar
version: 1.0.0
systemd:
  units:
    - name: nginx.service
      enabled: true
      contents: |
        [Unit]
        Description=NGINX example
        After=docker.service
        Requires=docker.service
        [Service]
        TimeoutStartSec=0
        ExecStartPre=-/usr/bin/docker rm --force nginx1
        ExecStart=/usr/bin/docker run --name nginx1 --pull always --log-driver=journald --net host docker.io/nginx:1
        ExecStop=/usr/bin/docker stop nginx1
        Restart=always
        RestartSec=5s
        [Install]
        WantedBy=multi-user.target

Transpile it to Ignition JSON:

cat cl.yaml | docker run --rm -i quay.io/coreos/butane:latest > ignition.json

Instance storage

Ephemeral disks and additional EBS volumes attached to instances can be mounted with a .mount unit. Amazon’s block storage devices are attached differently depending on the instance type . Here’s the Butane Config to format and mount the first ephemeral disk, xvdb, on most instance types:

variant: flatcar
version: 1.0.0
storage:
  filesystems:
    - device: /dev/xvdb
      format: ext4
      wipe_filesystem: true
      label: ephemeral
systemd:
  units:
    - name: media-ephemeral.mount
      enabled: true
      contents: |
        [Mount]
        What=/dev/disk/by-label/ephemeral
        Where=/media/ephemeral
        Type=ext4

        [Install]
        RequiredBy=local-fs.target

For more information about mounting storage, Amazon’s own documentation is the best source. You can also read about mounting storage on Flatcar Container Linux .

Adding more machines

To add more instances to the cluster, just launch more with the same Butane Config, the appropriate security group and the AMI for that region. New instances will join the cluster regardless of region if the security groups are configured correctly.

SSH to your instances

Flatcar Container Linux is set up to be a little more secure than other cloud images. By default, it uses the core user instead of root and doesn’t use a password for authentication. You’ll need to add an SSH key(s) via the AWS console or add keys/passwords via your Butane Config in order to log in.

To connect to an instance after it’s created, run:

ssh core@<ip address>

Multiple clusters

If you would like to create multiple clusters you will need to change the “Stack Name”. You can find the direct template file on S3 .

Manual setup

TL;DR: launch three instances of ami-04a78cf36bbf49fdd (amd64) in us-east-1 with a security group that has open port 22, 2379, 2380, 4001, and 7001 and the same “User Data” of each host. SSH uses the core user and you have etcd and Docker to play with.

Creating the security group

You need open port 2379, 2380, 7001 and 4001 between servers in the etcd cluster. Step by step instructions below.

Note: This step is only needed once

First we need to create a security group to allow Flatcar Container Linux instances to communicate with one another.

  1. Go to the security group page in the EC2 console.
  2. Click “Create Security Group”
    • Name: flatcar-testing
    • Description: Flatcar Container Linux instances
    • VPC: No VPC
    • Click: “Yes, Create”
  3. In the details of the security group, click the Inbound tab
  4. First, create a security group rule for SSH
    • Create a new rule: SSH
    • Source: 0.0.0.0/0
    • Click: “Add Rule”
  5. Add two security group rules for etcd communication
    • Create a new rule: Custom TCP rule
    • Port range: 2379
    • Source: type “flatcar-testing” until your security group auto-completes. Should be something like “sg-8d4feabc”
    • Click: “Add Rule”
    • Repeat this process for port range 2380, 4001 and 7001 as well
  6. Click “Apply Rule Changes”

Launching a test cluster

We will be launching three instances, with a few parameters in the User Data, and selecting our security group.

  • Open the quick launch wizard to boot: Alpha ami-04a78cf36bbf49fdd (amd64), Beta ami-090c7530884351c27 (amd64), or Stable ami-013922581faeb0980 (amd64)
  • On the second page of the wizard, launch 3 servers to test our clustering
    • Number of instances: 3, “Continue”
  • Paste your Ignition JSON config in the EC2 dashboard into the “User Data” field, “Continue”
  • Storage Configuration, “Continue”
  • Tags, “Continue”
  • Create Key Pair: Choose a key of your choice, it will be added in addition to the one in the gist, “Continue”
  • Choose one or more of your existing Security Groups: “flatcar-testing” as above, “Continue”
  • Launch!

Installation from a VMDK image

One of the possible ways of installation is to import the generated VMDK Flatcar image as a snapshot. The image file will be in https://${CHANNEL}.release.flatcar-linux.net/${ARCH}-usr/${VERSION}/flatcar_production_ami_vmdk_image.vmdk.bz2. Make sure you download the signature (it’s available in https://${CHANNEL}.release.flatcar-linux.net/${ARCH}-usr/${VERSION}/flatcar_production_ami_vmdk_image.vmdk.bz2.sig) and check it before proceeding.

$ wget https://alpha.release.flatcar-linux.net/amd64-usr/current/flatcar_production_ami_vmdk_image.vmdk.bz2
$ wget https://alpha.release.flatcar-linux.net/amd64-usr/current/flatcar_production_ami_vmdk_image.vmdk.bz2.sig
$ gpg --verify flatcar_production_ami_vmdk_image.vmdk.bz2.sig
gpg: assuming signed data in 'flatcar_production_ami_vmdk_image.vmdk.bz2'
gpg: Signature made Thu 15 Mar 2018 10:27:57 AM CET
gpg:                using RSA key A621F1DA96C93C639506832D603443A1D0FC498C
gpg: Good signature from "Flatcar Buildbot (Official Builds) <buildbot@flatcar-linux.org>" [ultimate]

Then, follow the instructions in Importing a Disk as a Snapshot Using VM Import/Export . You’ll need to upload the uncompressed vmdk file to S3.

After the snapshot is imported, you can go to “Snapshots” in the EC2 dashboard, and generate an AMI image from it. To make it work, use /dev/sda2 as the “Root device name” and you probably want to select “Hardware-assisted virtualization” as “Virtualization type”.

Using Flatcar Container Linux

Now that you have a machine booted it is time to play around. Check out the Flatcar Container Linux Quickstart guide or dig into more specific topics .

Terraform

The aws Terraform Provider allows to deploy machines in a declarative way. Read more about using Terraform and Flatcar here .

The following Terraform v0.13 module may serve as a base for your own setup. It will also take care of registering your SSH key at AWS EC2 and managing the network environment with Terraform.

You can clone the setup from the Flatcar Terraform examples repository or create the files manually as we go through them and explain each one.

git clone https://github.com/flatcar/flatcar-terraform.git
# From here on you could directly run it, TLDR:
cd aws
export AWS_ACCESS_KEY_ID=...
export AWS_SECRET_ACCESS_KEY=...
terraform init
# Edit the server configs or just go ahead with the default example
terraform plan
terraform apply

Start with a aws-ec2-machines.tf file that contains the main declarations:

terraform {
  required_version = ">= 0.13"
  required_providers {
    ct = {
      source  = "poseidon/ct"
      version = "0.7.1"
    }
    template = {
      source  = "hashicorp/template"
      version = "~> 2.2.0"
    }
    null = {
      source  = "hashicorp/null"
      version = "~> 3.0.0"
    }
    aws = {
      source  = "hashicorp/aws"
      version = "~> 3.19.0"
    }
  }
}

provider "aws" {
  region = var.aws_region
}

resource "aws_vpc" "network" {
  cidr_block = var.vpc_cidr

  tags = {
    Name = var.cluster_name
  }
}

resource "aws_subnet" "subnet" {
  vpc_id     = aws_vpc.network.id
  cidr_block = var.subnet_cidr

  tags = {
    Name = var.cluster_name
  }
}

resource "aws_internet_gateway" "gateway" {
  vpc_id = aws_vpc.network.id

  tags = {
    Name = var.cluster_name
  }
}

resource "aws_route_table" "default" {
  vpc_id = aws_vpc.network.id

  route {
    cidr_block = "0.0.0.0/0"
    gateway_id = aws_internet_gateway.gateway.id
  }

  tags = {
    Name = var.cluster_name
  }
}

resource "aws_route_table_association" "public" {
  route_table_id = aws_route_table.default.id
  subnet_id      = aws_subnet.subnet.id
}

resource "aws_security_group" "securitygroup" {
  vpc_id = aws_vpc.network.id

  tags = {
    Name = var.cluster_name
  }
}

resource "aws_security_group_rule" "outgoing_any" {
  security_group_id = aws_security_group.securitygroup.id
  type              = "egress"
  from_port         = 0
  to_port           = 0
  protocol          = "-1"
  cidr_blocks       = ["0.0.0.0/0"]
}

resource "aws_security_group_rule" "incoming_any" {
  security_group_id = aws_security_group.securitygroup.id
  type              = "ingress"
  from_port         = 0
  to_port           = 0
  protocol          = "-1"
  cidr_blocks       = ["0.0.0.0/0"]
}

resource "aws_key_pair" "ssh" {
  key_name   = var.cluster_name
  public_key = var.ssh_keys.0
}

data "aws_ami" "flatcar_stable_latest" {
  most_recent = true
  owners      = ["aws-marketplace"]

  filter {
    name   = "architecture"
    values = ["x86_64"]
  }

  filter {
    name   = "virtualization-type"
    values = ["hvm"]
  }

  filter {
    name   = "name"
    values = ["Flatcar-stable-*"]
  }
}

resource "aws_instance" "machine" {
  for_each      = toset(var.machines)
  instance_type = var.instance_type
  user_data     = data.ct_config.machine-ignitions[each.key].rendered
  ami           = data.aws_ami.flatcar_stable_latest.image_id
  key_name      = aws_key_pair.ssh.key_name

  associate_public_ip_address = true
  subnet_id                   = aws_subnet.subnet.id
  vpc_security_group_ids      = [aws_security_group.securitygroup.id]

  tags = {
    Name = "${var.cluster_name}-${each.key}"
  }
}

data "ct_config" "machine-ignitions" {
  for_each = toset(var.machines)
  content  = data.template_file.machine-configs[each.key].rendered
}

data "template_file" "machine-configs" {
  for_each = toset(var.machines)
  template = file("${path.module}/cl/machine-${each.key}.yaml.tmpl")

  vars = {
    ssh_keys = jsonencode(var.ssh_keys)
    name     = each.key
  }
}

Create a variables.tf file that declares the variables used above:

variable "machines" {
  type        = list(string)
  description = "Machine names, corresponding to cl/machine-NAME.yaml.tmpl files"
}

variable "cluster_name" {
  type        = string
  description = "Cluster name used as prefix for the machine names"
}

variable "ssh_keys" {
  type        = list(string)
  description = "SSH public keys for user 'core'"
}

variable "aws_region" {
  type        = string
  default     = "us-east-2"
  description = "AWS Region to use for running the machine"
}

variable "instance_type" {
  type        = string
  default     = "t3.medium"
  description = "Instance type for the machine"
}

variable "vpc_cidr" {
  type    = string
  default = "172.16.0.0/16"
}

variable "subnet_cidr" {
  type    = string
  default = "172.16.10.0/24"
}

An outputs.tf file shows the resulting IP addresses:

output "ip-addresses" {
  value = {
    for key in var.machines :
    "${var.cluster_name}-${key}" => aws_instance.machine[key].public_ip
  }
}

Now you can use the module by declaring the variables and a Container Linux Configuration for a machine. First create a terraform.tfvars file with your settings:

cluster_name           = "mycluster"
machines               = ["mynode"]
ssh_keys               = ["ssh-rsa AA... me@mail.net"]

The machine name listed in the machines variable is used to retrieve the corresponding Container Linux Config . For each machine in the list, you should have a machine-NAME.yaml.tmpl file with a corresponding name.

For example, create the configuration for mynode in the file machine-mynode.yaml.tmpl (The SSH key used there is not really necessary since we already set it as VM attribute):

---
passwd:
  users:
    - name: core
      ssh_authorized_keys:
        - ${ssh_keys}
storage:
  files:
    - path: /home/core/works
      filesystem: root
      mode: 0755
      contents:
        inline: |
          #!/bin/bash
          set -euo pipefail
           # This script demonstrates how templating and variable substitution works when using Terraform templates for Container Linux Configs.
          hostname="$(hostname)"
          echo My name is ${name} and the hostname is $${hostname}

Finally, run Terraform v0.13 as follows to create the machine:

export AWS_ACCESS_KEY_ID=...
export AWS_SECRET_ACCESS_KEY=...
terraform init
terraform apply

Log in via ssh core@IPADDRESS with the printed IP address (maybe add -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null).

When you make a change to machine-mynode.yaml.tmpl and run terraform apply again, the machine will be replaced.

You can find this Terraform module in the repository for Flatcar Terraform examples .