Architecture and access
Access entries
09 / 69

An access entry links an IAM principal to Kubernetes permissions, with no ConfigMap editing.

It replaces the old aws-auth ConfigMap, which was easy to break and could lock you out of your own cluster.

IAM principalrole or user, via SSOEKS access entryprincipal ARN + typeAccess policy and scopeAmazonEKSViewPolicy ... ClusterAdmincluster-wide or per namespaceKubernetes RBACor your own groups

Three authentication modes

CONFIG_MAP (old), API_AND_CONFIG_MAP (transition; the API wins), API (recommended). Switching is one-way: forward only.

Managed policies or your own groups

AWS provides access policies (view, edit, admin, cluster admin). For custom rules map an entry to a Kubernetes group and bind it with RBAC.

IaC and audit friendly

Entries are API objects: manage them in Terraform and see changes in CloudTrail. The cluster creator no longer has a hidden admin.

grant read access to one namespace
$ aws eks create-access-entry --cluster-name shop-eu --principal-arn arn:aws:iam::111122223333:role/dev-team
$ aws eks associate-access-policy --cluster-name shop-eu --principal-arn arn:aws:iam::111122223333:role/dev-team \
    --policy-arn arn:aws:eks::aws:cluster-access-policy/AmazonEKSViewPolicy --access-scope type=namespace,namespaces=shop