Choose how far the Kubernetes API is exposed, and who can get to it.
IAM authentication protects every mode, but a smaller exposure shrinks the attack surface. The cost is operational friction.
Public only (default)
Reachable from the internet
Authenticated by IAM and RBAC, but anyone can try. Acceptable for labs, rarely for production.
Public + private with allowlist
VPC direct, internet by CIDR
Nodes use the private path inside the VPC; engineers and CI come in from publicAccessCidrs only. The common production choice.
Private only
Only from the VPC
Smallest exposure. You need VPN, Direct Connect, a bastion or in-VPC CI runners for every kubectl call.
restrict the public endpoint
$ aws eks update-cluster-config --name shop-eu \
--resources-vpc-config \
endpointPublicAccess=true,endpointPrivateAccess=true,\
publicAccessCidrs="203.0.113.0/24"Private clusters need more plumbing
With no internet path, nodes need VPC endpoints (PrivateLink) for ECR, S3, STS and EC2, or a NAT gateway, to pull images and call AWS APIs.