Identity and security
Audit and detection
38 / 69

Control plane logs are off by default; enable the ones that answer 'who did what'.

Control plane log types

auditEvery API call: who, what, when. The forensic record.
authenticatorIAM to Kubernetes identity mapping events.
apiAPI server logs for troubleshooting.
controllerManager, schedulerReconciliation and scheduling diagnostics.
enable audit and authenticator logs
$ aws eks update-cluster-config --name shop-eu \
  --logging '{"clusterLogging":[{"enabled":true,
  "types":["api","audit","authenticator"]}]}'

Cost and retention

Logs go to CloudWatch Logs and can be large. Set retention, filter noisy users in the audit policy where possible, and consider shipping to S3.

guardduty iconGuardDuty EKS protection

Analyses audit logs for suspicious API activity and can add runtime monitoring on nodes.

cloudtrail iconCloudTrail

Records AWS-side actions such as access entry changes, role assumptions and cluster updates.

inspector iconInspector and ECR scanning

Finds vulnerabilities in images and node packages. Gate deployments on severity.