Amazon EKS now supports control plane egress through your VPC
Containers Blog
This article announces customer-routed control plane egress for Amazon EKS, enabling Kubernetes API Server traffic to route through your VPC instead of AWS-managed paths.
- Route admission webhooks, OIDC provider lookups, and aggregate API requests through your VPC
- Apply existing VPC routing, security groups, endpoints, and AWS Network Firewall controls to control plane traffic
- Enable private OIDC identity providers and private admission webhooks within your network perimeter
- Enforce organization-wide adoption using AWS Organizations Service Control Policies with eks:controlPlaneEgressMode condition key
- Set controlPlaneEgressMode to CUSTOMER_ROUTED at cluster creation or via update; setting is permanent and irreversible
- Capture complete audit trails through Amazon VPC Flow Logs for compliance requirements
- Works with EKS Auto Mode, managed node groups, Fargate, and existing tools like kubectl and Helm
- Available in all AWS Regions where EKS is supported with no additional charges
Customer-routed control plane egress enables regulated organizations to maintain complete control over Kubernetes control plane traffic routing while keeping authentication and policy decisions within their network perimeter.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.