How the managed control plane connects to your VPC
When you create a cluster you pass subnets in at least two Availability Zones. EKS provisions elastic network interfaces in those subnets. Those ENIs are how the AWS-operated API servers reach kubelets (for exec, logs, port-forward and admission webhooks) and how nodes reach the API server's private endpoint. A cluster security group is attached to them and to managed nodes.
Nodes bootstrap by contacting the cluster endpoint and authenticating with an IAM identity. For managed node groups and Auto Mode, EKS creates the entry that lets those nodes join; for self-managed nodes you map the node role yourself through an access entry. Nodes also need an IAM role to pull images from ECR and for the VPC CNI to manage ENIs.
Two design consequences. First, subnets are hard to change after creation, so plan them for growth: because the VPC CNI gives each Pod a real VPC IP address, a cluster's IP needs scale with Pods, not just nodes. Second, everything between the control plane and the nodes depends on security groups and routing in your VPC: a restrictive rule that blocks 443 or 10250 produces nodes that never join or exec that hangs.
Reveal the four steps: AWS's side, your VPC with the ENIs, the traffic between them, and the subnet sizing tip. A common production topology puts nodes in private subnets with NAT or VPC endpoints for ECR, S3 and STS, and public subnets only for load balancers.