Amazon EKS now supports customer-routed control plane egress
News
This article announces customer-routed control plane egress for Amazon EKS, enabling organizations to route outbound Kubernetes API server traffic through their own Amazon VPC.
- Route admission webhook callbacks, OIDC provider lookups, and aggregate API server requests through your VPC
- Control routing, security groups, and egress paths for API server traffic
- Access private OIDC providers and webhook servers within your VPC
- Set controlPlaneEgressMode to CUSTOMER_ROUTED when creating or updating clusters
- Enforce organization-wide using eks:controlPlaneEgressMode IAM condition key with SCPs
- Available at no additional cost in all AWS Regions where EKS is available
Customer-routed control plane egress helps organizations meet data perimeter requirements and compliance mandates by controlling how Kubernetes API traffic routes through their network.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.