By default, every pod deployed to an Amazon EKS cluster can run as root, mount host paths, and escalate privileges. Most teams don't realize this until a security review surfaces it. While certain system-level workloads genuinely need elevated access (Karpenter, for example, requires host-level permissions to manage nodes), application pods rarely do. Without restrictions, a … Continue reading Enforce Pod Security Standards on Amazon EKS
Tag: Kubernetes
Integrate AWS Secrets Manager with Amazon EKS using the Secrets Store CSI Driver
Containerized workloads on Amazon EKS often need access to sensitive credentials. A pod running a backend service might need a database connection string. A payment processor might require API keys. A message consumer might need authentication tokens for an external queue. In each case, the workload needs a way to retrieve secrets securely at runtime … Continue reading Integrate AWS Secrets Manager with Amazon EKS using the Secrets Store CSI Driver
Configure EKS Pod Identity for Secure AWS Access using Terraform
Containerized workloads running on Amazon EKS frequently need to interact with other AWS services. A pod running a web application might need to read secrets from AWS Secrets Manager. A monitoring agent might push metrics to CloudWatch. An autoscaler like Karpenter needs permissions to launch and terminate EC2 instances. In each case, the pod needs … Continue reading Configure EKS Pod Identity for Secure AWS Access using Terraform
Secure EKS API Access with Authentication and Authorization Controls using Terraform
Amazon EKS hosts containerized workloads, but any entity that needs to communicate with the cluster, whether to install addons, deploy applications via Helm, or check pod statuses with kubectl, must first have access to the cluster. By default, the IAM principal that creates the cluster receives implicit administrative access. However, for subsequent operations, a different … Continue reading Secure EKS API Access with Authentication and Authorization Controls using Terraform
Deploy Karpenter and Metrics Server on Amazon EKS using Terraform and Helm
Amazon EKS manages the control plane, but managing the data plane, the EC2 instances on which pods run, is the customer's responsibility. To provision data plane capacity, you create managed node groups backed by Auto Scaling Groups (ASGs), with a launch template that locks in instance types, capacity type (on-demand or spot), and scaling limits. … Continue reading Deploy Karpenter and Metrics Server on Amazon EKS using Terraform and Helm




