Secure Amazon container workloads using container attribute-based rules in AWS Network Firewall
Security Blog
This article explains how to secure containerized workloads on Amazon EKS and ECS using container attribute-based rules in AWS Network Firewall, eliminating the need to maintain static IP-based firewall rules.
- Define firewall rules using Kubernetes attributes (namespaces, pod names, labels, cluster names) instead of ephemeral IP addresses
- Network Firewall automatically discovers and tracks pods matching defined attributes, updating IP mappings in near real-time as pods scale or restart
- Enrich firewall alert logs with container context, enabling security teams to trace blocked or allowed traffic back to originating workloads
- Create container associations linking EKS clusters to Network Firewall, then reference them in Suricata-compatible stateful rules
- Supports Layer 7 inspection, FQDN-based filtering, TLS decryption, and managed IDS/IPS rules with no additional charges
- Requires SNAT to be disabled so Network Firewall can see pod IP addresses for granular pod-level egress controls
Container attribute-based rules simplify firewall management for dynamic Kubernetes environments while providing the same security capabilities as traditional applications.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2025
2025
2025
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.