Kubernetes on Amazon EKS: From First Cluster to Production Platform
Deck 3 of 7. A deep, visual, self-study course on Amazon EKS: architecture and access, managed node groups, Karpenter and Auto Mode, the VPC CNI and load balancing, Pod Identity and security, add-ons and storage, upgrades, observability and cost, with Shopwave scenarios, official AWS and Kubernetes icons, comprehensive infographic posters, a collapsible study-notes panel on every slide and a 15-question quiz.
Slides
Kubernetes on EKS, from first cluster to production platform
Cover for the EKS deep-dive deck.
Where this deck fits
The seven-deck path and the module list of the EKS deck.
EKS in 60 seconds: AWS runs the brain, you choose the muscle
Animated overview of the AWS-managed control plane and the customer-owned data plane.
EKS at a glance on one page
Revision poster for the orientation module.
Architecture and access: building the cluster and letting people in
Opens the architecture and access module.
How the managed control plane connects to your VPC
How EKS places network interfaces in customer subnets to connect the control plane and nodes.
Creating clusters: eksctl, Terraform or the console
Compares eksctl, Terraform and the console for provisioning EKS clusters.
Who can reach the API server: public, restricted or private
The three API endpoint access modes and when to use each.
IAM identities become Kubernetes permissions through access entries
EKS access entries, authentication modes and how they map IAM to Kubernetes RBAC.
EKS versions have a clock: standard, then extended support
EKS Kubernetes version support windows and what they imply for upgrade cadence.
Beyond the standard cluster: provisioned control plane, hybrid nodes, EKS Anywhere
Overview of standard, provisioned control plane, hybrid nodes and EKS Anywhere options.
Access, endpoint and versions on one page
Revision poster for the architecture and access module.
Compute: four ways to get nodes for your Pods
Opens the compute module.
Managed node groups: an Auto Scaling group with EKS manners
Managed node groups and what AWS manages versus what you choose.
Node images: Amazon Linux or Bottlerocket, and how to harden them
Node OS choices (Amazon Linux versus Bottlerocket) and IMDSv2 hardening.
Fargate: one microVM per Pod, no nodes to manage
Fargate profiles, how Pods are matched, and the main constraints.
Karpenter: provision the node a pending Pod actually needs
Animated Karpenter provisioning flow from a Pending Pod to a new node.
NodePool and EC2NodeClass: what may launch, and how
Anatomy of Karpenter NodePool and EC2NodeClass resources.
Consolidation and Spot: continuously cheaper, safely
Karpenter consolidation, Spot interruption handling and disruption budgets.
EKS Auto Mode: AWS operates the nodes, and more
What EKS Auto Mode manages compared with standard EKS and when to choose it.
Choosing a compute model
Decision tree among Auto Mode, Karpenter, managed node groups and Fargate.
Compute on one page
Revision poster for the compute module.
Networking: pods are VPC citizens
Opens the EKS networking module.
The VPC CNI gives each Pod a real address from its node's ENIs
How the Amazon VPC CNI assigns VPC IPs to Pods through ENI secondary addresses.
Running out of IPs: prefix delegation, custom networking and IPv6
Prefix delegation, custom networking and IPv6 as responses to IP exhaustion.
Isolation: security groups for pods and network policy
Security groups for pods versus Kubernetes NetworkPolicy.
AWS Load Balancer Controller: ALB for HTTP, NLB for TCP
How the AWS Load Balancer Controller provisions ALBs and NLBs and targets Pods.
Gateway API on EKS: two controllers, two scopes
Two Gateway API paths on EKS: ALB/NLB through the Load Balancer Controller and VPC Lattice.
VPC Lattice: services across clusters and accounts
VPC Lattice cross-cluster and cross-account service connectivity with Gateway API.
Private clusters: endpoints, egress and DNS
VPC endpoints required for a private EKS cluster and how they compare with NAT.
Cross-AZ traffic: the hidden latency and cost line
How cross-AZ traffic costs arise and how topology-aware routing reduces them.
EKS networking on one page
Revision poster for the networking module.
Identity and security: no long-lived keys, layered defences
Opens the identity and security module.
EKS Pod Identity: temporary AWS credentials per ServiceAccount
Animated EKS Pod Identity credential exchange.
Pod Identity or IRSA, and how to migrate
IRSA versus Pod Identity comparison and migration steps.
Secrets: keep the source of truth outside the cluster
Secrets management on EKS with Secrets Manager integration and KMS encryption.
An EKS hardening checklist by layer
EKS hardening checklist grouped by node, control plane, workload and network layers.
Turn on the logs and detections before you need them
Control plane log types and the AWS detection services for EKS.
Images and admission: control what runs
Supply chain controls from build to admission on EKS.
Identity and security on one page
Revision poster for the identity and security module.
Add-ons and storage: the parts that make a cluster useful
Opens the add-ons and storage module.
Managed add-ons: versioned, health-checked, and safe to update
EKS managed add-ons and conflict resolution modes.
EBS volumes: fast, zonal, ReadWriteOnce
EBS CSI provisioning flow and zone implications.
Shared and object storage: EFS, FSx and Mountpoint for S3
EFS, FSx and Mountpoint for S3 as shared and object storage options on EKS.
Add-ons and storage on one page
Revision poster for the add-ons and storage module.
Operations: upgrades, scaling, observability and cost
Opens the operations module.
Upgrade in order: control plane, add-ons, then nodes
The fixed upgrade order for an EKS cluster with preparation and verification.
Node upgrades: in place, blue and green, or drift
In-place, blue/green and Karpenter drift node upgrade strategies.
Pre-upgrade checks that catch most failures
Checklist and commands for pre-upgrade validation.
Scaling stack: HPA adds Pods, Karpenter adds nodes
How the HPA and Karpenter cooperate to scale Pods and nodes.
Observability on EKS: metrics, logs and traces
EKS observability components and how to choose between them.
Where EKS money goes and the levers that matter
Cost levers for EKS ordered by typical impact.
GitOps on EKS: let a controller pull the desired state
GitOps with Argo CD or Flux on EKS and the access model it enables.
Sharing a cluster: three tenancy models on EKS
Soft, partial hard and hard tenancy models and their EKS mechanisms.
Operations on one page
Revision poster for the operations module.
Real-world EKS: a platform, a migration, an incident review
Opens the real-world EKS module.
Shopwave's EKS landing zone
Reference architecture of Shopwave's EKS landing zone with the AWS services around the cluster.
Migrating from Cluster Autoscaler to Karpenter, safely
Stepwise migration from Cluster Autoscaler to Karpenter.
EKS and GKE side by side
Comparison of EKS and GKE across compute, networking, identity, ingress, upgrades and cost.
Three EKS incidents and the mechanism behind each
Three EKS incident case studies covering IP exhaustion, add-on overwrite and access mapping.
EKS command cheat sheet
Grouped aws, eksctl and kubectl commands for clusters, nodes, identity and networking.
The Karpenter migration on one page
Revision poster for the migration scenario.
What you should be able to explain now
Recap checklist for the EKS deck.
Quiz 1 of 5: Architecture, access and compute
Questions 1 to 3 with Check answer and explanations.
Quiz 2 of 5: Compute and networking
Questions 4 to 6 with Check answer and explanations.
Quiz 3 of 5: Networking, Auto Mode and Fargate
Questions 7 to 9 with Check answer and explanations.
Quiz 4 of 5: Identity, add-ons and storage
Questions 10 to 12 with Check answer and explanations.
Quiz 5 of 5: Add-ons, storage and operations
Questions 13 to 15 with Check answer and explanations.
Your score and what to review
Score summary and a map from missed questions to modules.