Security on EKS

Overview

EKS provides multiple layers of security for clusters and workloads. AWS and customers share responsibility for security.

Topics

Cluster Access & Authentication

Pod Authentication

Secrets Management

Additional Security

Shared Responsibility

AWS ResponsibleCustomer Responsible
Control planeNode OS hardening
Kubernetes softwareContainer security
Managed node updatesNetwork policies
Security patchesIAM configuration
etcd encryptionSecrets encryption

References