---
title: Control plane configuration options for Amazon Web Services
---

# Control plane configuration options for Amazon Web Services {#cpmso-config-options-aws}

You can update your control plane machines to reflect changes in your infrastructure or environment by editing values in the control plane machine set specification.

When you save an update to the control plane machine set, the Control Plane Machine Set Operator updates the control plane machines according to your configured update strategy. For more information, see "Updating the control plane configuration".

The following example YAML snippets show provider specification and failure domain configurations for an AWS cluster.

## Sample AWS provider specification {#cpmso-yaml-provider-spec-aws_cpmso-config-options-aws}

You can update your control plane machines to reflect changes in your underlying infrastructure by editing values in the control plane machine set provider specification.

The following example YAML illustrates a valid configuration for an Amazon Web Services (AWS) cluster.

> [!NOTE]
> When you create a control plane machine set for an existing cluster, the provider specification must match the `providerSpec` configuration in the control plane machine custom resource (CR) that the installation program creates.

You can omit any field that has a value set in the failure domain section of the CR.

In the following example, the `<cluster_id>` string is the infrastructure ID. The infrastructure ID matches the cluster ID that the installation program used during cluster provisioning. If you have the OpenShift CLI (`oc`) installed, you can obtain the infrastructure ID by running the following command:

```terminal
$ oc get -o jsonpath='{.status.infrastructureName}{"\n"}' infrastructure cluster
```

```yaml {title="Sample AWS providerSpec values"}
apiVersion: machine.openshift.io/v1
kind: ControlPlaneMachineSet
metadata:
  name: cluster
  namespace: openshift-machine-api
spec:
# ...
  template:
# ...
      spec:
        providerSpec:
          value:
            ami:
              id: ami-<ami_id_string>
            apiVersion: machine.openshift.io/v1beta1
            blockDevices:
            - ebs:
                encrypted: true
                iops: 0
                kmsKey:
                  arn: ""
                volumeSize: 120
                volumeType: gp3
            credentialsSecret:
              name: aws-cloud-credentials
            deviceIndex: 0
            iamInstanceProfile:
              id: <cluster_id>-master-profile
            instanceType: m6i.xlarge
            kind: AWSMachineProviderConfig
            loadBalancers:
            - name: <cluster_id>-int
              type: network
            - name: <cluster_id>-ext
              type: network
            metadata:
              creationTimestamp: null
            metadataServiceOptions: {}
            placement:
              region: <region>
              availabilityZone: ""
              tenancy:
            securityGroups:
              - filters:
                - name: tag:Name
                  values:
                  - <cluster_id>-node
              - filters:
                - name: tag:Name
                  values:
                  - <cluster_id>-lb
              - filters:
                - name: tag:Name
                  values:
                  - <cluster_id>-controlplane
            subnet: {}
            userDataSecret:
              name: master-user-data
```

where:

`<ami_id_string>`
:   Specifies the Red Hat Enterprise Linux CoreOS (RHCOS) Amazon Machine Images (AMI) ID for the cluster. The AMI must belong to the same region as the cluster. If you want to use an AWS Marketplace image, you must complete the OpenShift Container Platform subscription from the [AWS Marketplace](https://aws.amazon.com/marketplace/fulfillment?productId=59ead7de-2540-4653-a8b0-fa7926d5c845) to obtain an AMI ID for your region.

`spec.template.spec.providerSpec.value.blockDevices.ebs`
:   Specifies the configuration of an encrypted Amazon Elastic Block Store (Amazon EBS) volume.

`spec.template.spec.providerSpec.value.credentialsSecret.name`
:   Specifies the secret name for the cluster. Do not change this value.

`spec.template.spec.providerSpec.value.iamInstanceProfile`
:   Specifies the AWS Identity and Access Management (IAM) instance profile. Do not change this value.

`spec.template.spec.providerSpec.value.instanceType`
:   Specifies the AWS instance type for the control plane.

`spec.template.spec.providerSpec.value.kind`
:   Specifies the cloud provider platform type. Do not change this value.

`spec.template.spec.providerSpec.value.loadBalancers`
:   Specifies the internal (`int`) and external (`ext`) load balancers for the cluster.

    > [!NOTE]
    > You can omit the external (`ext`) load balancer parameters on private OpenShift Container Platform clusters.

`spec.template.spec.providerSpec.value.placement`
:   Specifies where to create the control plane instance in AWS. The following keys in this stanza specify additional details:

`region`
:   Specifies the AWS region for the cluster.

`availabilityZone`
:   This parameter is in the failure domain configuration and has an empty value here.

    If the cluster uses a failure domain, configure this parameter in the failure domain. If you specify this value in the provider specification when using a failure domain, the Control Plane Machine Set Operator ignores it and uses the value in the failure domain.

`tenancy`
:   Specifies the AWS Dedicated Instance configuration for the control plane. For more information, see AWS documentation about [Dedicated Instances](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-instance.html). The following values are valid:

    - `default`: The Dedicated Instance runs on shared hardware.
    - `dedicated`: The Dedicated Instance runs on single-tenant hardware.
    - `host`: The Dedicated Instance runs on a Dedicated Host, which is an isolated server with configurations that you can control.

`spec.template.spec.providerSpec.value.securityGroups`
:   Specifies the control plane machines security group.

`spec.template.spec.providerSpec.value.subnet`
:   This parameter is in the failure domain configuration and has an empty value here.

    If the cluster uses a failure domain, configure this parameter in the failure domain. If you specify this value in the provider specification when using a failure domain, the Control Plane Machine Set Operator ignores it and uses the value in the failure domain.

    > [!NOTE]
    > If the failure domain configuration does not specify a value, the control plane machines use the value in the provider specification.

`spec.template.spec.providerSpec.value.userDataSecret`
:   Specifies the control plane user data secret. Do not change this value.

## Sample AWS failure domain configuration {#cpmso-yaml-failure-domain-aws_cpmso-config-options-aws}

To prevent downtime for your applications due to the failure of a single Amazon Web Services (AWS) region, you can configure failure domains in the control plane machine set by configuring appropriate values in the `failureDomains` section of the `ControlPlaneMachineSet` object.

The control plane machine set concept of a failure domain is analogous to the AWS concept of an [*Availability Zone (AZ)*](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-regions-availability-zones.html#concepts-availability-zones). The `ControlPlaneMachineSet` CR spreads control plane machines across more than one failure domain when possible.

When configuring AWS failure domains in the control plane machine set, you must specify the availability zone name and the subnet to use.

```yaml {title="Sample AWS failure domain values"}
apiVersion: machine.openshift.io/v1
kind: ControlPlaneMachineSet
metadata:
  name: cluster
  namespace: openshift-machine-api
spec:
# ...
  template:
# ...
    machines_v1beta1_machine_openshift_io:
      failureDomains:
        aws:
        - placement:
            availabilityZone: <aws_zone_a>
          subnet:
            filters:
            - name: tag:Name
              values:
              - <cluster_id>-subnet-private-<aws_zone_a>
            type: Filters
        - placement:
            availabilityZone: <aws_zone_b>
          subnet:
            filters:
            - name: tag:Name
              values:
              - <cluster_id>-subnet-private-<aws_zone_b>
            type: Filters
        platform: AWS
# ...
```

where:

`spec.template.machines_v1beta1_machine_openshift_io.failureDomains.aws.placement.availabilityZone: <aws_zone_a>`
:   Specifies an AWS availability zone for the first failure domain.

`spec.template.machines_v1beta1_machine_openshift_io.failureDomains.aws.subnet`
:   Specifies a subnet configuration. In this example, the subnet type is `Filters`, so there is a `filters` stanza.

`spec.template.machines_v1beta1_machine_openshift_io.failureDomains.aws.subnet.filters.values: <cluster_id>-subnet-private-<aws_zone_a>`
:   Specifies the subnet name for the first failure domain, using the infrastructure ID and the AWS availability zone.

`spec.template.machines_v1beta1_machine_openshift_io.failureDomains.aws.subnet.type`
:   Specifies the subnet type. The following values are valid: `ARN`, `Filters` and `ID`. The default value is `Filters`.

`spec.template.machines_v1beta1_machine_openshift_io.failureDomains.aws.placement.availabilityZone: <aws_zone_b>`
:   Specifies an AWS availability zone for an additional failure domain.

`spec.template.machines_v1beta1_machine_openshift_io.failureDomains.aws.subnet.filters.values: <cluster_id>-subnet-private-<aws_zone_b>`
:   Specifies the subnet name for the additional failure domain, using the infrastructure ID and the AWS availability zone.

`spec.template.machines_v1beta1_machine_openshift_io.failureDomains.platform`
:   Specifies the cloud provider platform name. Do not change this value.

**Additional resources**
{._additional-resources}

- [Updating the control plane configuration](/openshift-docs-markdown/machine_management/control_plane_machine_management/cpmso-managing-machines#cpmso-feat-config-update_cpmso-managing-machines)
- [Configuring Amazon Web Services features for control plane machines](/openshift-docs-markdown/machine_management/control_plane_machine_management/cpmso_provider_configurations/cpmso-supported-features-aws#cpmso-supported-features-aws)
