This SOP covers the AWS commands needed to create a standalone VPC, subnets, route table, security group, and peering connection. It also covers the prerequisites needed to install an RDS and ElastiCache instance in the standalone VPC
- AWS CLI login
- OpenShift-created cluster VPC to establish a peering connection with
STANDALONE_VPC_ID=$(aws ec2 create-vpc \
--cidr-block \
--tag-specification 'ResourceType=vpc,Tags=[{Key=Name,Value=StandaloneVPC}]' \
--query Vpc.VpcId --output text)
aws ec2 modify-vpc-attribute \
--enable-dns-hostnames "{\"Value\":true}"
aws ec2 modify-vpc-attribute \
--enable-dns-support "{\"Value\":true}"
Note: Make sure to replace the with the region the standalone VPC is in
STANDALONE_SUBNET_1_ID=$(aws ec2 create-subnet \
--cidr-block \
--availability-zone ${REGION}a \
--tag-specification 'ResourceType=subnet,Tags=[{Key=Name,Value=StandaloneVPC-PrivateSubnet1}]' \
--query 'Subnet.SubnetId' --output text)
STANDALONE_SUBNET_2_ID=$(aws ec2 create-subnet \
--cidr-block \
--availability-zone ${REGION}b \
--tag-specification 'ResourceType=subnet,Tags=[{Key=Name,Value=StandaloneVPC-PrivateSubnet2}]' \
--query 'Subnet.SubnetId' --output text)
STANDALONE_SECURITY_GROUP_ID=$(aws ec2 create-security-group \
--group-name standalonesecuritygroup --description "security group for standalone VPC" \
--tag-specification 'ResourceType=security-group,Tags=[{Key=Name,Value=StandaloneVPC-SecurityGroup}]' \
--query 'GroupId' --output text)
aws ec2 authorize-security-group-ingress \
--group-id $STANDALONE_SECURITY_GROUP_ID --protocol -1 \
Note: specifying -1
for the protocol indicates the rule should be applied for all traffic
First get the ID of the cluster VPC which can be found using the red-hat-managed
tag and assign the value to an environment variable
CLUSTER_VPC_ID=$(aws ec2 describe-vpcs \
--filters Name=tag:red-hat-managed,Values=true \
--query 'Vpcs[].VpcId[]' --output text)
Now create the peering connection
PEERING_CONNECTION_ID=$(aws ec2 create-vpc-peering-connection \
--peer-vpc-id $CLUSTER_VPC_ID \
--query 'VpcPeeringConnection.VpcPeeringConnectionId' --output text)
aws ec2 accept-vpc-peering-connection \
--vpc-peering-connection-id $PEERING_CONNECTION_ID
First get the ID(s) of the route table(s) associated with the standalone VPC
aws ec2 describe-route-tables --filters Name=vpc-id,Values=$STANDALONE_VPC_ID --query 'RouteTables[].RouteTableId' --output text
For each of the returned route tables, create a route linking cluster VPC and peering connection
Make sure to update the value of STANDALONE_RT_ID as needed for each of the returned route tables
aws ec2 create-route --route-table-id $STANDALONE_RT_ID --destination-cidr-block --vpc-peering-connection-id $PEERING_CONNECTION_ID
First get the ID(s) of the route table(s) associated with the cluster VPC
aws ec2 describe-route-tables --filters Name=vpc-id,Values=$CLUSTER_VPC_ID --query 'RouteTables[].RouteTableId' --output text
For each of the returned route tables, create a route linking cluster VPC and peering connection
Make sure to update the value of CLUSTER_RT_ID as needed for each of the returned route tables
aws ec2 create-route --route-table-id $CLUSTER_RT_ID --destination-cidr-block --vpc-peering-connection-id $PEERING_CONNECTION_ID
aws rds create-db-subnet-group \
--db-subnet-group-name standalonesubnetgroup \
--db-subnet-group-description "Subnet group created for standalone VPC" \
--subnet-ids '["'${STANDALONE_SUBNET_1_ID}'","'${STANDALONE_SUBNET_2_ID}'"]'
aws elasticache create-cache-subnet-group \
--cache-subnet-group-name standalonesubnetgroup \
--cache-subnet-group-description "Subnet group created for standalone VPC" \
--subnet-ids '["'${STANDALONE_SUBNET_1_ID}'","'${STANDALONE_SUBNET_2_ID}'"]'