Home icon

Session policies for Amazon EKS Pod Identity

Containers Blog



This article announces session policies for Amazon EKS Pod Identity, enabling dynamic permission scoping for Kubernetes pods without creating multiple IAM roles.

  • Dynamically restrict IAM permissions for pods using inline session policies
  • Avoid creating separate IAM roles for each permission variation
  • Permissions are intersection of IAM role and session policy
  • Supports same-account and cross-account access via IAM role chaining
  • Session tags and session policies cannot be used together
  • Session policies limited to 2,048 characters
  • Includes step-by-step walkthrough for S3 bucket access restriction
  • Available across all AWS regions where EKS is supported

Session policies provide fine-grained permission control for EKS workloads while maintaining security boundaries and following least privilege principles.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 14
2024
Amazon EKS open sources Pod Identity agent
Jun 12
2025
Amazon EKS Pod Identity streamlines cross account access
Jun 12
2025
Amazon EKS Pod Identity simplifies the experience for cross-account access
Mar 10
2025
Simplifying IAM Permissions for Amazon EKS Addons with EKS Pod Identity

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.