Module 1
Architecture and access
A cluster is more than eksctl create cluster. You decide how it is provisioned, which networks can reach its API, and how IAM identities map to Kubernetes permissions.
Why it matters. Locked-out clusters, over-exposed API endpoints and surprise extended-support charges are all decisions made in the first hour. Make them deliberately.
After this module you can answer
- How is an EKS cluster actually wired into my VPC?
- eksctl, Terraform or the console: which for what?
- Public, private or restricted API endpoint?
- How do access entries replace the aws-auth ConfigMap?
- What does Kubernetes version support cost and mean?
What is inside
1Control plane and VPC
2Creating clusters
3API endpoint access
4Access entries
5Version lifecycle
6Beyond the standard cluster
7Module infographic