An access entry links an IAM principal to Kubernetes permissions, with no ConfigMap editing.
It replaces the old aws-auth ConfigMap, which was easy to break and could lock you out of your own cluster.
Three authentication modes
CONFIG_MAP (old), API_AND_CONFIG_MAP (transition; the API wins), API (recommended). Switching is one-way: forward only.
Managed policies or your own groups
AWS provides access policies (view, edit, admin, cluster admin). For custom rules map an entry to a Kubernetes group and bind it with RBAC.
IaC and audit friendly
Entries are API objects: manage them in Terraform and see changes in CloudTrail. The cluster creator no longer has a hidden admin.
grant read access to one namespace
$ aws eks create-access-entry --cluster-name shop-eu --principal-arn arn:aws:iam::111122223333:role/dev-team $ aws eks associate-access-policy --cluster-name shop-eu --principal-arn arn:aws:iam::111122223333:role/dev-team \ --policy-arn arn:aws:eks::aws:cluster-access-policy/AmazonEKSViewPolicy --access-scope type=namespace,namespaces=shop