HTML Deck

Kubernetes on Amazon EKS: From First Cluster to Production Platform

Deck 3 of 7. A deep, visual, self-study course on Amazon EKS: architecture and access, managed node groups, Karpenter and Auto Mode, the VPC CNI and load balancing, Pod Identity and security, add-ons and storage, upgrades, observability and cost, with Shopwave scenarios, official AWS and Kubernetes icons, comprehensive infographic posters, a collapsible study-notes panel on every slide and a 15-question quiz.

69 slides16:9 widescreenHTML + CSS + JSSand & Orange
Live preview

Slides

01Preview slide

Kubernetes on EKS, from first cluster to production platform

Cover for the EKS deep-dive deck.

02Preview slide

Where this deck fits

The seven-deck path and the module list of the EKS deck.

03Preview slide

EKS in 60 seconds: AWS runs the brain, you choose the muscle

Animated overview of the AWS-managed control plane and the customer-owned data plane.

04Preview slide

EKS at a glance on one page

Revision poster for the orientation module.

05Preview slide

Architecture and access: building the cluster and letting people in

Opens the architecture and access module.

06Preview slide

How the managed control plane connects to your VPC

How EKS places network interfaces in customer subnets to connect the control plane and nodes.

07Preview slide

Creating clusters: eksctl, Terraform or the console

Compares eksctl, Terraform and the console for provisioning EKS clusters.

08Preview slide

Who can reach the API server: public, restricted or private

The three API endpoint access modes and when to use each.

09Preview slide

IAM identities become Kubernetes permissions through access entries

EKS access entries, authentication modes and how they map IAM to Kubernetes RBAC.

10Preview slide

EKS versions have a clock: standard, then extended support

EKS Kubernetes version support windows and what they imply for upgrade cadence.

11Preview slide

Beyond the standard cluster: provisioned control plane, hybrid nodes, EKS Anywhere

Overview of standard, provisioned control plane, hybrid nodes and EKS Anywhere options.

12Preview slide

Access, endpoint and versions on one page

Revision poster for the architecture and access module.

13Preview slide

Compute: four ways to get nodes for your Pods

Opens the compute module.

14Preview slide

Managed node groups: an Auto Scaling group with EKS manners

Managed node groups and what AWS manages versus what you choose.

15Preview slide

Node images: Amazon Linux or Bottlerocket, and how to harden them

Node OS choices (Amazon Linux versus Bottlerocket) and IMDSv2 hardening.

16Preview slide

Fargate: one microVM per Pod, no nodes to manage

Fargate profiles, how Pods are matched, and the main constraints.

17Preview slide

Karpenter: provision the node a pending Pod actually needs

Animated Karpenter provisioning flow from a Pending Pod to a new node.

18Preview slide

NodePool and EC2NodeClass: what may launch, and how

Anatomy of Karpenter NodePool and EC2NodeClass resources.

19Preview slide

Consolidation and Spot: continuously cheaper, safely

Karpenter consolidation, Spot interruption handling and disruption budgets.

20Preview slide

EKS Auto Mode: AWS operates the nodes, and more

What EKS Auto Mode manages compared with standard EKS and when to choose it.

21Preview slide

Choosing a compute model

Decision tree among Auto Mode, Karpenter, managed node groups and Fargate.

22Preview slide

Compute on one page

Revision poster for the compute module.

23Preview slide

Networking: pods are VPC citizens

Opens the EKS networking module.

24Preview slide

The VPC CNI gives each Pod a real address from its node's ENIs

How the Amazon VPC CNI assigns VPC IPs to Pods through ENI secondary addresses.

25Preview slide

Running out of IPs: prefix delegation, custom networking and IPv6

Prefix delegation, custom networking and IPv6 as responses to IP exhaustion.

26Preview slide

Isolation: security groups for pods and network policy

Security groups for pods versus Kubernetes NetworkPolicy.

27Preview slide

AWS Load Balancer Controller: ALB for HTTP, NLB for TCP

How the AWS Load Balancer Controller provisions ALBs and NLBs and targets Pods.

28Preview slide

Gateway API on EKS: two controllers, two scopes

Two Gateway API paths on EKS: ALB/NLB through the Load Balancer Controller and VPC Lattice.

29Preview slide

VPC Lattice: services across clusters and accounts

VPC Lattice cross-cluster and cross-account service connectivity with Gateway API.

30Preview slide

Private clusters: endpoints, egress and DNS

VPC endpoints required for a private EKS cluster and how they compare with NAT.

31Preview slide

Cross-AZ traffic: the hidden latency and cost line

How cross-AZ traffic costs arise and how topology-aware routing reduces them.

32Preview slide

EKS networking on one page

Revision poster for the networking module.

33Preview slide

Identity and security: no long-lived keys, layered defences

Opens the identity and security module.

34Preview slide

EKS Pod Identity: temporary AWS credentials per ServiceAccount

Animated EKS Pod Identity credential exchange.

35Preview slide

Pod Identity or IRSA, and how to migrate

IRSA versus Pod Identity comparison and migration steps.

36Preview slide

Secrets: keep the source of truth outside the cluster

Secrets management on EKS with Secrets Manager integration and KMS encryption.

37Preview slide

An EKS hardening checklist by layer

EKS hardening checklist grouped by node, control plane, workload and network layers.

38Preview slide

Turn on the logs and detections before you need them

Control plane log types and the AWS detection services for EKS.

39Preview slide

Images and admission: control what runs

Supply chain controls from build to admission on EKS.

40Preview slide

Identity and security on one page

Revision poster for the identity and security module.

41Preview slide

Add-ons and storage: the parts that make a cluster useful

Opens the add-ons and storage module.

42Preview slide

Managed add-ons: versioned, health-checked, and safe to update

EKS managed add-ons and conflict resolution modes.

43Preview slide

EBS volumes: fast, zonal, ReadWriteOnce

EBS CSI provisioning flow and zone implications.

44Preview slide

Shared and object storage: EFS, FSx and Mountpoint for S3

EFS, FSx and Mountpoint for S3 as shared and object storage options on EKS.

45Preview slide

Add-ons and storage on one page

Revision poster for the add-ons and storage module.

46Preview slide

Operations: upgrades, scaling, observability and cost

Opens the operations module.

47Preview slide

Upgrade in order: control plane, add-ons, then nodes

The fixed upgrade order for an EKS cluster with preparation and verification.

48Preview slide

Node upgrades: in place, blue and green, or drift

In-place, blue/green and Karpenter drift node upgrade strategies.

49Preview slide

Pre-upgrade checks that catch most failures

Checklist and commands for pre-upgrade validation.

50Preview slide

Scaling stack: HPA adds Pods, Karpenter adds nodes

How the HPA and Karpenter cooperate to scale Pods and nodes.

51Preview slide

Observability on EKS: metrics, logs and traces

EKS observability components and how to choose between them.

52Preview slide

Where EKS money goes and the levers that matter

Cost levers for EKS ordered by typical impact.

53Preview slide

GitOps on EKS: let a controller pull the desired state

GitOps with Argo CD or Flux on EKS and the access model it enables.

54Preview slide

Sharing a cluster: three tenancy models on EKS

Soft, partial hard and hard tenancy models and their EKS mechanisms.

55Preview slide

Operations on one page

Revision poster for the operations module.

56Preview slide

Real-world EKS: a platform, a migration, an incident review

Opens the real-world EKS module.

57Preview slide

Shopwave's EKS landing zone

Reference architecture of Shopwave's EKS landing zone with the AWS services around the cluster.

58Preview slide

Migrating from Cluster Autoscaler to Karpenter, safely

Stepwise migration from Cluster Autoscaler to Karpenter.

59Preview slide

EKS and GKE side by side

Comparison of EKS and GKE across compute, networking, identity, ingress, upgrades and cost.

60Preview slide

Three EKS incidents and the mechanism behind each

Three EKS incident case studies covering IP exhaustion, add-on overwrite and access mapping.

61Preview slide

EKS command cheat sheet

Grouped aws, eksctl and kubectl commands for clusters, nodes, identity and networking.

62Preview slide

The Karpenter migration on one page

Revision poster for the migration scenario.

63Preview slide

What you should be able to explain now

Recap checklist for the EKS deck.

64Preview slide

Quiz 1 of 5: Architecture, access and compute

Questions 1 to 3 with Check answer and explanations.

65Preview slide

Quiz 2 of 5: Compute and networking

Questions 4 to 6 with Check answer and explanations.

66Preview slide

Quiz 3 of 5: Networking, Auto Mode and Fargate

Questions 7 to 9 with Check answer and explanations.

67Preview slide

Quiz 4 of 5: Identity, add-ons and storage

Questions 10 to 12 with Check answer and explanations.

68Preview slide

Quiz 5 of 5: Add-ons, storage and operations

Questions 13 to 15 with Check answer and explanations.

69Preview slide

Your score and what to review

Score summary and a map from missed questions to modules.