Orientation
Overview
03 / 69

The control plane is AWS's; the nodes, add-ons and workloads are yours to choose and run.

Your kubectl talks to an AWS-operated API server. Network interfaces in your own subnets connect it to the nodes in your VPC.

AWS-managed accountEKS control planeAPI servers + etcdacross several Availability ZonesAWS patches, scales and backs upthe control plane for youIAM authenticates every requestYour VPCAvailability Zone Aworker nodeworker nodeprivate subnetAvailability Zone Bworker nodeworker nodeprivate subnetAvailability Zone Cworker nodeworker nodeprivate subnetNodes: managed node groups, Karpenter, Auto Mode or FargateYou also run add-ons (CNI, CoreDNS, CSI) and your workloadsENIs inyour subnetsAWS runs: control plane, etcd, API high availabilityYou run: nodes, add-ons, workloads, access, upgrades of the data plane