Revision poster: who runs what on EKS.

Left: AWS's side. Right: your VPC and worker nodes. The strip underneath splits the responsibilities.
- 1AWS operates the Kubernetes API servers and etcd across several Availability Zones.
- 2ENIs in your subnets connect the control plane to your nodes.
- 3Nodes may be EC2 (managed groups, Karpenter), Auto Mode or Fargate.
- 4IAM authenticates people and workloads; Kubernetes RBAC authorizes them.
- 5You run add-ons, workloads, access and data-plane upgrades.
Self-check: cover the poster and answer
- Which parts of the cluster can you never SSH into?
- What connects the AWS-managed control plane to your nodes?
AWS runs the control plane; you decide how much of the data plane to own.