Creating a Kubernetes cluster via the console or CLI is deceptively easy. eksctl create cluster gives you a running EKS cluster in 15 minutes. But that cluster is not production-ready. It has default networking (no private endpoints), default node configuration (no taints, labels, or optimized AMIs), default security (no pod security policies or network policies), and no add-ons (no ingress controller, no cert-manager, no monitoring).
Making the cluster production-ready requires configuring all of these components, and doing it manually means it is not reproducible. When you need a second cluster for staging, disaster recovery, or a new region, you are starting from scratch. With IaC, spinning up an identical cluster is a single command.
Cluster configuration also changes over time. Kubernetes versions need upgrading, node pools need resizing, add-ons need updating, and security policies need tightening. Doing these changes through IaC means they go through code review, have a plan showing the expected impact, and can be rolled back if something goes wrong. This is especially critical for version upgrades, which can break workloads if not handled carefully.