Control plane logs are off by default; enable the ones that answer 'who did what'.
Control plane log types
| audit | Every API call: who, what, when. The forensic record. |
| authenticator | IAM to Kubernetes identity mapping events. |
| api | API server logs for troubleshooting. |
| controllerManager, scheduler | Reconciliation and scheduling diagnostics. |
enable audit and authenticator logs
$ aws eks update-cluster-config --name shop-eu \
--logging '{"clusterLogging":[{"enabled":true,
"types":["api","audit","authenticator"]}]}'Cost and retention
Logs go to CloudWatch Logs and can be large. Set retention, filter noisy users in the audit policy where possible, and consider shipping to S3.
Analyses audit logs for suspicious API activity and can add runtime monitoring on nodes.
Records AWS-side actions such as access entry changes, role assumptions and cluster updates.
Finds vulnerabilities in images and node packages. Gate deployments on severity.