Networking
VPC CNI
24 / 69

Pod capacity per node is set by how many ENIs and secondary IPs the instance type allows.

Each ENI holds a number of IPv4 addresses; the primary IP belongs to the node, the rest are handed to Pods.

EC2 node (m5.large) in a private subnet 10.0.1.0/24ENI 1 (primary)node IP 10.0.1.4.10.11.12secondary IPs are warm for new PodsENI 2 (attached as needed)more secondary IPs.20.21.22checkout 10.0.1.10catalog 10.0.1.11payments 10.0.1.20orders 10.0.1.21

Max Pods per node (default mode)

ENIs x (IPs per ENI - 1) + 2

m5.large: 3 x (10 - 1) + 2 = 29 Pods. Small instances run out of Pod slots long before CPU.

Why this design

No overlay or NAT: Pods use native VPC routing, security groups and flow logs, and are reachable from on-prem over Direct Connect.

The catch

Every Pod consumes a subnet IP. A big cluster in a small /24 subnet fails to schedule Pods long before CPU is full.