Architecture and access
API endpoint
08 / 69

Choose how far the Kubernetes API is exposed, and who can get to it.

IAM authentication protects every mode, but a smaller exposure shrinks the attack surface. The cost is operational friction.

Public only (default)
internetgateway iconReachable from the internet

Authenticated by IAM and RBAC, but anyone can try. Acceptable for labs, rarely for production.

Public + private with allowlist
vpc iconVPC direct, internet by CIDR

Nodes use the private path inside the VPC; engineers and CI come in from publicAccessCidrs only. The common production choice.

Private only
directconnect iconOnly from the VPC

Smallest exposure. You need VPN, Direct Connect, a bastion or in-VPC CI runners for every kubectl call.

restrict the public endpoint
$ aws eks update-cluster-config --name shop-eu \
    --resources-vpc-config \
    endpointPublicAccess=true,endpointPrivateAccess=true,\
publicAccessCidrs="203.0.113.0/24"

Private clusters need more plumbing

With no internet path, nodes need VPC endpoints (PrivateLink) for ECR, S3, STS and EC2, or a NAT gateway, to pull images and call AWS APIs.