Architecture and access
Architecture
06 / 69

EKS creates network interfaces in your subnets so the control plane and your nodes can talk.

You give EKS at least two subnets in two Availability Zones. Nodes join through the cluster endpoint with IAM-based bootstrap.

AWS-managed VPCKubernetes API servermultiple instancesetcdreplicated across zonesNo access for you: AWS operates itYour VPCsubnet in zone AEKS ENInodesubnet in zone BEKS ENInodeCluster security group: allows control plane to node traffic (kubelet 10250) and node to API (443)Node IAM role (or Pod Identity) lets nodes join and pull images from ECRTip: size subnets generously, because pods will use VPC IPs too (Module 3)