Amazon EKS now supports AWS PrivateLink for the cluster OIDC endpoint
News
This article announces AWS PrivateLink support for Amazon EKS cluster OIDC discovery and JWKS endpoints, enabling private access for IAM roles for service accounts (IRSA).
- Access OIDC endpoints privately from VPC without internet egress requirements
- Tools like eksctl, Terraform, and custom validators can reach OIDC discovery documents privately
- Create interface VPC endpoint for com.amazonaws.<region>.oidc-eks service
- Enables IRSA setup and token validation in isolated VPCs
- Available at no additional cost beyond standard AWS PrivateLink pricing
- Supported in all AWS Regions where Amazon EKS is available
This enhancement improves security and operational flexibility for EKS clusters by eliminating internet egress requirements for OIDC endpoint access.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Aug 24
2026
2026
Amazon EKS now supports multiple external OIDC identity providers per cluster
Jun 12
2026
2026
Amazon EKS now supports local clusters on AWS Outposts with Amazon EC2 instance store
Aug 12
2026
2026
Amazon EKS now supports advanced Kubernetes control plane configuration parameters
Jul 1
2026
2026
Amazon EKS now supports Kubernetes version rollback
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.