All Products
Search
Document Center

Resource Orchestration Service:ALIYUN::CS::ClusterAddons

Last Updated:Jul 24, 2026

The ALIYUN::CS::ClusterAddons type is used to install addons for a specified cluster.

Syntax

{
  "Type": "ALIYUN::CS::ClusterAddons",
  "Properties": {
    "ClusterId": String,
    "Addons": List,
    "InstalledIgnore": Boolean,
    "WaitUntil": List,
    "OverrideExisting": Boolean,
    "RolePolicy": String,
    "ValidationMode": String
  }
}

Properties

Property

Type

Required

Editable

Description

Constraints

Addons

List

Yes

Yes

List of addon configuration information.

For more information, see Addons properties.

ClusterId

String

Yes

No

Cluster ID.

None

InstalledIgnore

Boolean

No

No

Whether to ignore already installed addons when creating the cluster.

Valid values:

  • true: Ignores already installed addons. When creating the cluster, only uninstalled addons are installed. When deleting the cluster, only addons installed during creation are uninstalled.

  • false (default): Does not ignore already installed addons.

OverrideExisting

Boolean

No

No

Whether to override the configuration of already installed addons during creation.

If true, existing addons will have their configurations overridden during creation, and non-existing addons will be installed; during deletion, only addons installed during creation are uninstalled. Cannot be used together with InstalledIgnore. Default value: false.

RolePolicy

String

No

Yes

Before deploying the application, check the policies associated with the current user's role.

Valid values:

  • EnsureAdminRoleAndBinding (default): Automatically creates a role named ros:application-admin:${user-id} with administrator permissions and binds it to the current user.

  • None: No action is performed.

ValidationMode

String

No

No

Validation mode.

Valid values:

  • Basic: Basic validation, such as verifying that the cluster exists.

  • Strict: In addition to basic validation, also validates the validity of WaitUntil.

WaitUntil

List

No

Yes

After starting creation or update, wait until all conditions are met.

For more information, see WaitUntil properties.

Addons syntax

"Addons": [
  {
    "Version": String,
    "Config": String,
    "Name": String
  }
]

Addons properties

Property

Type

Required

Editable

Description

Constraints

Name

String

Yes

No

Addon name.

None

Config

String

No

Yes

Addon configuration information.

None

Version

String

No

No

Addon version.

None

WaitUntil syntax

"WaitUntil": [
  {
   "ApiVersion": String,
   "FirstMatch": Boolean,
   "Timeout": Integer,
   "JsonPath": String,
   "Namespace": String,
   "Stage": String,
   "Name": String,
   "ValueType": String,
   "Kind": String,
   "Value": String,
   "Operator": String
  }
]

WaitUntil properties

Property

Type

Required

Editable

Description

Constraints

Kind

String

Yes

Yes

The Kubernetes resource type to query.

None

Name

String

Yes

Yes

The Kubernetes resource name to query.

None

Operator

String

Yes

Yes

The operator used to compare the value with the result of the JsonPath expression.

None

ApiVersion

String

No

Yes

API version.

None

FirstMatch

Boolean

No

Yes

Returns only the first match from the JsonPath filter results.

Valid values:

  • true

  • false (default)

JsonPath

String

No

Yes

JSON path expression used to filter the output.

None

Namespace

String

No

Yes

The Kubernetes namespace where the resource resides.

Default value: DefaultNamespace.

Stage

String

No

No

The stage at which to wait.

Valid values:

  • Create/Update (default): Creation and update stages.

  • Delete: Deletion stage.

Timeout

Integer

No

Yes

The timeout period for waiting until conditions are met.

Unit: seconds.

Value

String

No

Yes

The value to compare with the result of the JsonPath expression.

None

ValueType

String

No

Yes

The type of the value.

Default value: String.

Return values

Fn::GetAtt

  • ClusterId: The cluster ID.

  • WaitUntilData: The list of values for each JsonPath in WaitUntil.

Examples

Scenario 1: Install basic network and logging addons for an ACK cluster

ROSTemplateFormatVersion: '2015-09-01'
Description:
  zh-cn: 为ACK集群安装基础网络和日志组件。
  en: Install basic network and logging addons for an ACK cluster.
Parameters:
  ClusterId:
    Type: String
    Label:
      zh-cn: 集群ID
      en: Cluster ID
    Description:
      zh-cn: ACK集群的唯一标识,可在容器服务控制台获取。
      en: The unique identifier of the ACK cluster, available in the Container Service console.
    AssociationProperty: ALIYUN::CS::Cluster::ClusterId
Resources:
  ClusterAddons:
    Type: ALIYUN::CS::ClusterAddons
    Properties:
      ClusterId:
        Ref: ClusterId
      Addons:
        - Name: flannel
        - Name: logtail-ds
      InstalledIgnore: true
Outputs:
  ClusterId:
    Label:
      zh-cn: 集群ID
      en: Cluster ID
    Description:
      zh-cn: 已安装组件的ACK集群ID。
      en: The ACK cluster ID with addons installed.
    Value:
      Fn::GetAtt:
        - ClusterAddons
        - ClusterId
{
  "ROSTemplateFormatVersion": "2015-09-01",
  "Description": {
    "zh-cn": "为ACK集群安装基础网络和日志组件。",
    "en": "Install basic network and logging addons for an ACK cluster."
  },
  "Parameters": {
    "ClusterId": {
      "Type": "String",
      "Label": {
        "zh-cn": "集群ID",
        "en": "Cluster ID"
      },
      "Description": {
        "zh-cn": "ACK集群的唯一标识,可在容器服务控制台获取。",
        "en": "The unique identifier of the ACK cluster, available in the Container Service console."
      },
      "AssociationProperty": "ALIYUN::CS::Cluster::ClusterId"
    }
  },
  "Resources": {
    "ClusterAddons": {
      "Type": "ALIYUN::CS::ClusterAddons",
      "Properties": {
        "ClusterId": {
          "Ref": "ClusterId"
        },
        "Addons": [
          {
            "Name": "flannel"
          },
          {
            "Name": "logtail-ds"
          }
        ],
        "InstalledIgnore": true
      }
    }
  },
  "Outputs": {
    "ClusterId": {
      "Label": {
        "zh-cn": "集群ID",
        "en": "Cluster ID"
      },
      "Description": {
        "zh-cn": "已安装组件的ACK集群ID。",
        "en": "The ACK cluster ID with addons installed."
      },
      "Value": {
        "Fn::GetAtt": [
          "ClusterAddons",
          "ClusterId"
        ]
      }
    }
  }
}

Scenario 2: Install Ingress and monitoring addons for an ACK cluster with version pinning and custom configuration

ROSTemplateFormatVersion: '2015-09-01'
Description:
  zh-cn: 为ACK集群安装Ingress和监控组件,指定版本和自定义配置。
  en: Install Ingress and monitoring addons with version pinning and custom config.
Parameters:
  ClusterId:
    Type: String
    Label:
      zh-cn: 集群ID
      en: Cluster ID
    Description:
      zh-cn: 目标ACK集群的唯一标识。
      en: The unique identifier of the target ACK cluster.
    AssociationProperty: ALIYUN::CS::Cluster::ClusterId
  IngressVersion:
    Type: String
    Label:
      zh-cn: Ingress组件版本
      en: Ingress Addon Version
    Description:
      zh-cn: >-
        Nginx Ingress Controller的版本号。
        留空则安装最新版本。
      en: >-
        Version of Nginx Ingress Controller.
        Leave empty to install the latest version.
    Default: ''
  IngressReplicas:
    Type: Number
    Label:
      zh-cn: Ingress副本数
      en: Ingress Replicas
    Description:
      zh-cn: Nginx Ingress Controller的副本数量,生产环境建议至少2个副本。
      en: Number of Nginx Ingress Controller replicas. At least 2 replicas recommended for production.
    Default: 2
    MinValue: 1
    MaxValue: 10
  RolePolicy:
    Type: String
    Label:
      zh-cn: 角色策略
      en: Role Policy
    Description:
      zh-cn: >-
        部署组件前的角色检查策略。
        EnsureAdminRoleAndBinding:自动创建管理员角色并绑定。
        None:不执行角色操作。
      en: >-
        Role check policy before deploying addons.
        EnsureAdminRoleAndBinding: auto-create admin role and bindingit.
        None: skip role operations.
    Default: EnsureAdminRoleAndBinding
    AllowedValues:
      - EnsureAdminRoleAndBinding
      - None
Resources:
  ClusterAddons:
    Type: ALIYUN::CS::ClusterAddons
    Properties:
      ClusterId:
        Ref: ClusterId
      InstalledIgnore: true
      RolePolicy:
        Ref: RolePolicy
      Addons:
        - Name: nginx-ingress-controller
          Version:
            Ref: IngressVersion
          Config:
            Fn::Sub:
              - '{"IngressSlbNetworkType":"internet","IngressSlbSpec":"slb.s2.small","IngressReplicaCount":${Replicas}}'
              - Replicas:
                  Ref: IngressReplicas
        - Name: arms-prometheus
Outputs:
  ClusterId:
    Label:
      zh-cn: 集群ID
      en: Cluster ID
    Value:
      Fn::GetAtt:
        - ClusterAddons
        - ClusterId
{
  "ROSTemplateFormatVersion": "2015-09-01",
  "Description": {
    "zh-cn": "为ACK集群安装Ingress和监控组件,指定版本和自定义配置。",
    "en": "Install Ingress and monitoring addons with version pinning and custom config."
  },
  "Parameters": {
    "ClusterId": {
      "Type": "String",
      "Label": {
        "zh-cn": "集群ID",
        "en": "Cluster ID"
      },
      "Description": {
        "zh-cn": "目标ACK集群的唯一标识。",
        "en": "The unique identifier of the target ACK cluster."
      },
      "AssociationProperty": "ALIYUN::CS::Cluster::ClusterId"
    },
    "IngressVersion": {
      "Type": "String",
      "Label": {
        "zh-cn": "Ingress组件版本",
        "en": "Ingress Addon Version"
      },
      "Description": {
        "zh-cn": "Nginx Ingress Controller的版本号。留空则安装最新版本。",
        "en": "Version of Nginx Ingress Controller. Leave empty to install the latest version."
      },
      "Default": ""
    },
    "IngressReplicas": {
      "Type": "Number",
      "Label": {
        "zh-cn": "Ingress副本数",
        "en": "Ingress Replicas"
      },
      "Description": {
        "zh-cn": "Nginx Ingress Controller的副本数量,生产环境建议至少2个副本。",
        "en": "Number of Nginx Ingress Controller replicas. At least 2 replicas recommended for production."
      },
      "Default": 2,
      "MinValue": 1,
      "MaxValue": 10
    },
    "RolePolicy": {
      "Type": "String",
      "Label": {
        "zh-cn": "角色策略",
        "en": "Role Policy"
      },
      "Description": {
        "zh-cn": "部署组件前的角色检查策略。EnsureAdminRoleAndBinding:自动创建管理员角色并绑定。None:不执行角色操作。",
        "en": "Role check policy before deploying addons. EnsureAdminRoleAndBinding: auto-create admin role and bind it. None: skip role operations."
      },
      "Default": "EnsureAdminRoleAndBinding",
      "AllowedValues": [
        "EnsureAdminRoleAndBinding",
        "None"
      ]
    }
  },
  "Resources": {
    "ClusterAddons": {
      "Type": "ALIYUN::CS::ClusterAddons",
      "Properties": {
        "ClusterId": {
          "Ref": "ClusterId"
        },
        "InstalledIgnore": true,
        "RolePolicy": {
          "Ref": "RolePolicy"
        },
        "Addons": [
          {
            "Name": "nginx-ingress-controller",
            "Version": {
              "Ref": "IngressVersion"
            },
            "Config": {
              "Fn::Sub": [
                "{\"IngressSlbNetworkType\":\"internet\",\"IngressSlbSpec\":\"slb.s2.small\",\"IngressReplicaCount\":${Replicas}}",
                {
                  "Replicas": {
                    "Ref": "IngressReplicas"
                  }
                }
              ]
            }
          },
          {
            "Name": "arms-prometheus"
          }
        ]
      }
    }
  },
  "Outputs": {
    "ClusterId": {
      "Label": {
        "zh-cn": "集群ID",
        "en": "Cluster ID"
      },
      "Value": {
        "Fn::GetAtt": [
          "ClusterAddons",
          "ClusterId"
        ]
      }
    }
  }
}

Scenario 3: Install a complete production-grade addon suite for an ACK cluster and use WaitUntil to wait for addon readiness before continuing deployment

ROSTemplateFormatVersion: '2015-09-01'
Description:
  zh-cn: 为ACK集群安装完整的生产级组件套件,使用WaitUntil等待组件就绪。
  en: Install a full production addon suite for ACK with WaitUntil readiness checks.
Parameters:
  ClusterId:
    Type: String
    Label:
      zh-cn: 集群ID
      en: Cluster ID
    Description:
      zh-cn: 目标ACK集群的唯一标识。
      en: The unique identifier of the target ACK cluster.
    AssociationProperty: ALIYUN::CS::Cluster::ClusterId
  IngressReplicas:
    Type: Number
    Label:
      zh-cn: Ingress副本数
      en: Ingress Replicas
    Description:
      zh-cn: Nginx Ingress Controller的副本数量。
      en: Number of Nginx Ingress Controller replicas.
    Default: 2
    MinValue: 1
    MaxValue: 10
  WaitTimeout:
    Type: Number
    Label:
      zh-cn: 组件就绪超时时间(秒)
      en: Addon Readiness Timeout (seconds)
    Description:
      zh-cn: >-
        等待组件就绪的超时时间,单位为秒。
        超时后资源栈将回滚。建议根据集群规模适当调大。
      en: >-
        Timeout for waiting addon readiness, in seconds.
        Stack will roll back on timeout. Increase for larger clusters.
    Default: 300
    MinValue: 60
    MaxValue: 1800
Resources:
  ClusterAddons:
    Type: ALIYUN::CS::ClusterAddons
    Properties:
      ClusterId:
        Ref: ClusterId
      InstalledIgnore: true
      RolePolicy: EnsureAdminRoleAndBinding
      ValidationMode: Strict
      Addons:
        - Name: terway-eniip
        - Name: coredns
        - Name: nginx-ingress-controller
          Config:
            Fn::Sub:
              - '{"IngressSlbNetworkType":"internet","IngressSlbSpec":"slb.s2.small","IngressReplicaCount":${Replicas}}'
              - Replicas:
                  Ref: IngressReplicas
        - Name: arms-prometheus
      WaitUntil:
        - Kind: Deployment
          Name: coredns
          Namespace: kube-system
          JsonPath: $.status.readyReplicas
          Value: '1'
          Operator: NotEmpty
          Timeout:
            Ref: WaitTimeout
          Stage: Create/Update
          ApiVersion: apps/v1
          FirstMatch: true
        - Kind: DaemonSet
          Name: terway-eniip
          Namespace: kube-system
          JsonPath: $.status.numberReady
          Value: '1'
          Operator: NotEmpty
          Timeout:
            Ref: WaitTimeout
          Stage: Create/Update
          ApiVersion: apps/v1
          FirstMatch: true
Outputs:
  ClusterId:
    Label:
      zh-cn: 集群ID
      en: Cluster ID
    Description:
      zh-cn: 已完成生产级组件部署的ACK集群ID。
      en: The ACK cluster ID with production addons deployed.
    Value:
      Fn::GetAtt:
        - ClusterAddons
        - ClusterId
  WaitUntilData:
    Label:
      zh-cn: 组件就绪检查结果
      en: Addon Readiness Check Results
    Description:
      zh-cn: WaitUntil中每个JsonPath的值列表,用于验证组件是否已就绪。
      en: The value list for each JsonPath in WaitUntil, for verifying addon readiness.
    Value:
      Fn::GetAtt:
        - ClusterAddons
        - WaitUntilData
{
  "ROSTemplateFormatVersion": "2015-09-01",
  "Description": {
    "zh-cn": "为ACK集群安装完整的生产级组件套件,使用WaitUntil等待组件就绪。",
    "en": "Install a full production addon suite for ACK with WaitUntil readiness checks."
  },
  "Parameters": {
    "ClusterId": {
      "Type": "String",
      "Label": {
        "zh-cn": "集群ID",
        "en": "Cluster ID"
      },
      "Description": {
        "zh-cn": "目标ACK集群的唯一标识。",
        "en": "The unique identifier of the target ACK cluster."
      },
      "AssociationProperty": "ALIYUN::CS::Cluster::ClusterId"
    },
    "IngressReplicas": {
      "Type": "Number",
      "Label": {
        "zh-cn": "Ingress副本数",
        "en": "Ingress Replicas"
      },
      "Description": {
        "zh-cn": "Nginx Ingress Controller的副本数量。",
        "en": "Number of Nginx Ingress Controller replicas."
      },
      "Default": 2,
      "MinValue": 1,
      "MaxValue": 10
    },
    "WaitTimeout": {
      "Type": "Number",
      "Label": {
        "zh-cn": "组件就绪超时时间(秒)",
        "en": "Addon Readiness Timeout (seconds)"
      },
      "Description": {
        "zh-cn": "等待组件就绪的超时时间,单位为秒。超时后资源栈将回滚。建议根据集群规模适当调大。",
        "en": "Timeout for waiting addon readiness, in seconds. Stack will roll back on timeout. Increase for larger clusters."
      },
      "Default": 300,
      "MinValue": 60,
      "MaxValue": 1800
    }
  },
  "Resources": {
    "ClusterAddons": {
      "Type": "ALIYUN::CS::ClusterAddons",
      "Properties": {
        "ClusterId": {
          "Ref": "ClusterId"
        },
        "InstalledIgnore": true,
        "RolePolicy": "EnsureAdminRoleAndBinding",
        "ValidationMode": "Strict",
        "Addons": [
          {
            "Name": "terway-eniip"
          },
          {
            "Name": "coredns"
          },
          {
            "Name": "nginx-ingress-controller",
            "Config": {
              "Fn::Sub": [
                "{\"IngressSlbNetworkType\":\"internet\",\"IngressSlbSpec\":\"slb.s2.small\",\"IngressReplicaCount\":${Replicas}}",
                {
                  "Replicas": {
                    "Ref": "IngressReplicas"
                  }
                }
              ]
            }
          },
          {
            "Name": "arms-prometheus"
          }
        ],
        "WaitUntil": [
          {
            "Kind": "Deployment",
            "Name": "coredns",
            "Namespace": "kube-system",
            "JsonPath": "$.status.readyReplicas",
            "Value": "1",
            "Operator": "NotEmpty",
            "Timeout": {
              "Ref": "WaitTimeout"
            },
            "Stage": "Create/Update",
            "ApiVersion": "apps/v1",
            "FirstMatch": true
          },
          {
            "Kind": "DaemonSet",
            "Name": "terway-eniip",
            "Namespace": "kube-system",
            "JsonPath": "$.status.numberReady",
            "Value": "1",
            "Operator": "NotEmpty",
            "Timeout": {
              "Ref": "WaitTimeout"
            },
            "Stage": "Create/Update",
            "ApiVersion": "apps/v1",
            "FirstMatch": true
          }
        ]
      }
    }
  },
  "Outputs": {
    "ClusterId": {
      "Label": {
        "zh-cn": "集群ID",
        "en": "Cluster ID"
      },
      "Description": {
        "zh-cn": "已完成生产级组件部署的ACK集群ID。",
        "en": "The ACK cluster ID with production addons deployed."
      },
      "Value": {
        "Fn::GetAtt": [
          "ClusterAddons",
          "ClusterId"
        ]
      }
    },
    "WaitUntilData": {
      "Label": {
        "zh-cn": "组件就绪检查结果",
        "en": "Addon Readiness Check Results"
      },
      "Description": {
        "zh-cn": "WaitUntil中每个JsonPath的值列表,用于验证组件是否已就绪。",
        "en": "The value list for each JsonPath in WaitUntil, for verifying addon readiness."
      },
      "Value": {
        "Fn::GetAtt": [
          "ClusterAddons",
          "WaitUntilData"
        ]
      }
    }
  }
}