Home icon

Amazon EKS now supports control plane egress through your VPC

Containers Blog



This article announces customer-routed control plane egress for Amazon EKS, enabling Kubernetes API Server traffic to route through your VPC instead of AWS-managed paths.

  • Route admission webhooks, OIDC provider lookups, and aggregate API requests through your VPC
  • Apply existing VPC routing, security groups, endpoints, and AWS Network Firewall controls to control plane traffic
  • Enable private OIDC identity providers and private admission webhooks within your network perimeter
  • Enforce organization-wide adoption using AWS Organizations Service Control Policies with eks:controlPlaneEgressMode condition key
  • Set controlPlaneEgressMode to CUSTOMER_ROUTED at cluster creation or via update; setting is permanent and irreversible
  • Capture complete audit trails through Amazon VPC Flow Logs for compliance requirements
  • Works with EKS Auto Mode, managed node groups, Fargate, and existing tools like kubectl and Helm
  • Available in all AWS Regions where EKS is supported with no additional charges

Customer-routed control plane egress enables regulated organizations to maintain complete control over Kubernetes control plane traffic routing while keeping authentication and policy decisions within their network perimeter.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 18
2026
Amazon EKS now supports customer-routed control plane egress
Nov 27
2025
Amazon EKS introduces Provisioned Control Plane
Nov 21
2025
Amazon EKS introduces Provisioned Control Plane
Nov 18
2024
Amazon EKS enhances Kubernetes control plane observability

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.