< ciso
brief />
Tag Banner

All news with #aws eks tag

76 articles

AWS Network Firewall adds wildcard for container filters

πŸ”’ AWS Network Firewall now supports wildcard matching in container attribute-based inspection filters for Amazon EKS and Amazon ECS, allowing administrators to define patterns that match multiple container workloads in a single rule. This eliminates the need to create individual container associations for each variant and simplifies management in dynamic container environments. Wildcard patterns such as app=payments-* automatically cover variants like payments-api, payments-worker, and payments-cron. The feature is available in all Regions where container attribute-based inspection is supported.
read more β†’

AWS Batch adds EKS access entry authentication

πŸ› οΈ AWS Batch now supports Amazon EKS access entry authentication for compute environments. EKS access entries provide an API-driven way to grant IAM principals access to Kubernetes clusters, complementing the existing aws-auth ConfigMap. To enable, set accessEntry.desiredState to ENABLED via the CreateComputeEnvironment or UpdateComputeEnvironment APIs; AWS Batch creates one access entry per cluster and attaches the AWSBatchClusterPolicy. This feature is available in all Regions where AWS Batch is offered.
read more β†’

Amazon EKS Distro Adds Kubernetes 1.37 Support

πŸš€ Amazon EKS and EKS Distro now support Kubernetes version 1.37. This release lets you create new clusters or upgrade existing ones via the EKS console, eksctl, or infrastructure-as-code tools. Kubernetes 1.37 promotes the Metrics API to GA, graduates Dynamic Resource Allocation device taints and tolerations to GA, and enables HPA scale-to-zero by default. EKS 1.37 is available in all Regions where EKS operates, with EKS Distro images published to ECR Public Gallery and GitHub.
read more β†’

EKS Auto Mode adds advanced node tuning options

πŸš€ Amazon EKS Auto Mode now supports advanced node tuning via the NodeClass resource, enabling kubelet, Linux kernel sysctl, and hugepage configuration directly through the Kubernetes API. advancedCompute lets you set user namespaces for rootless builds, adjust eviction thresholds and log rotation, raise network and ARP cache limits, and pre-allocate 2Mi or 1Gi hugepages for HPC and low-latency workloads. EKS Auto Mode validates and applies settings at node boot and preserves them across scaling and upgrades, with no custom AMIs, EC2 launch templates, or privileged DaemonSets to manage.
read more β†’

EMR on EKS adds interactive Spark Connect sessions

πŸ”₯ Amazon EMR on EKS now supports interactive Apache Spark sessions via Spark Connect, enabling data engineers and scientists to develop and debug Spark applications from managed notebooks in Amazon SageMaker Unified Studio or their own IDEs like Jupyter and VS Code. An interactive session provides a persistent Spark context that spans cells and scripts, blending local Python execution with remote Spark operations on EKS. Sessions run as pods on virtual clusters secured by IAM execution roles and tagged by project and user, and Spark Connect is available in EMR release 7.14 (Spark 3.5) and emr-spark-8.1.0 (Spark 4.1) across AWS Commercial Regions.
read more β†’

SageMaker HyperPod Inference Gateway Launch

πŸš€ Amazon SageMaker HyperPod Inference Gateway is a Kubernetes-native, GPU-aware routing add-on for EKS that integrates with existing SageMaker HyperPod infrastructure without application changes. It replaces round-robin balancing with real-time inference-signal-driven routing to reduce first-token latency by up to 82% and p99 TTFT by 97–98% in mixed-hardware and burst scenarios. The Gateway comprises an Envoy Endpoint, a Body-Based Router that reads model names from requests, and an Endpoint Picker that scores pods across six inference-level signals to select the optimal target. It supports OpenAI-compatible model servers like vLLM and SGLang, is available per-cluster in supported Regions, and will soon add cross-cluster, cross-region routing and centralized traffic controls.
read more β†’

Amazon EMR on EKS adds IPv6 support

πŸš€ Amazon announces that Amazon EMR on EKS now supports running Spark and Flink workloads on IPv6 Amazon EKS clusters. This enables teams to use the larger IPv6 address space to scale high-executor analytics jobs without IPv4 workarounds. Support starts with EMR releases emr-7.14.0 and emr-spark-8.0.0 and is available in regions where IPv6 EKS clusters are offered.
read more β†’

Amazon EMR introduces Long Term Support for Spark

πŸš€ Amazon EMR launches Long Term Support (LTS) starting with emr-spark-8.1.0, which includes Apache Spark 4.1 and offers 36 months of support for designated AWS Spark runtimes. The release adds full support for Apache Iceberg v3, expanded fine-grained access control for Iceberg and Delta VACUUM operations, and Spark SQL improvements for catalog discovery and cross-account catalogs. emr-spark-8.1.0 is available across Amazon EMR on EC2, EKS, and Serverless in all regions.
read more β†’

Amazon EMR 7.14 release expands platform capabilities

πŸš€ Amazon EMR 7.14 adds platform-wide enhancements across Amazon EMR on EC2, Amazon EMR on EKS, and Amazon EMR Serverless, and upgrades key components including Apache Spark to 3.5.8 and Apache Iceberg to 1.10.1. Iceberg materialized views refresh faster by using change data capture to limit file reads. EMR on EKS supports Spark Connect endpoints with token-based authentication and IPv6 clusters, while EMR Serverless increases Spark job storage from 200 GiB to 1 TiB. The release is available in all Regions where Amazon EMR is offered.
read more β†’

AWS Resilience Hub adds EKS labels, insights, sharing

πŸ”§ AWS Resilience Hub introduces three capabilities: EKS labels as service input sources, generative AI-powered dependency insights, and resilience policy sharing via AWS Organizations. EKS labels let teams scope discovery using Kubernetes labeling conventions. Dependency insights analyze discovered dependencies to surface new links, cross-Region dependencies, and unusual patterns. Policy sharing enables centralized policy distribution and organization-wide observability.
read more β†’

Elastic Beanstalk adds Cluster Mode for pooled apps

πŸš€ AWS Elastic Beanstalk introduces Cluster Mode, a deployment option that runs multiple applications on shared, EKS-powered infrastructure. Provide source code, a Dockerfile, or an Amazon ECR image and Elastic Beanstalk handles containerization, provisioning, and lifecycle operations via the console, CLI, APIs, or a new GitHub Action. Cluster Mode supports autoscaling, OpenTelemetry observability, AWS Secrets Manager, and HTTPS via AWS Certificate Manager, and is available in all commercial AWS Regions where Elastic Beanstalk is offered.
read more β†’

Amazon EMR on EKS adds job admission controls

πŸ”” Amazon EMR on EKS now supports job run admission control with configurable concurrency and queue depth limits. You submit jobs to a virtual cluster mapped to an EKS namespace and EMR on EKS manages packaging, scheduling, and execution. Configure maxConcurrentJobRuns and maxInQueueJobRuns to protect shared clusters from overload and noisy-neighbor failures. When the queue is full, StartJobRun returns an HTTP ValidationException; view limits and counts with DescribeVirtualCluster.
read more β†’

Mountpoint for S3 adds configurable memory limits

🧩 Mountpoint for Amazon S3 now supports configurable memory usage limits, either set manually or determined automatically based on the runtime environment. This change lets Mountpoint coexist with memory‑intensive workloads such as machine learning training or analytics by reserving memory for applications and slowing operations under memory pressure. The feature detects container budgets in environments like Amazon EKS and is available in all AWS Regions. Upgrade details and configuration guidance are available in the Mountpoint GitHub repository.
read more β†’

Amazon EKS adds support for multiple OIDC providers

πŸ”’ Amazon Elastic Kubernetes Service (Amazon EKS) now lets you associate up to 10 external OpenID Connect (OIDC) identity providers with a single cluster. This enables distinct user populationsβ€”employees, contractors, CI/CD systemsβ€”to authenticate directly without consolidating providers or using an identity broker. Each provider is configured and managed independently and coexists with existing IAM authentication. You add providers via the AWS Management Console or the AssociateIdentityProviderConfig API at no extra cost in all EKS regions.
read more β†’

Amazon EKS Argo CD now supports custom configuration

πŸ”§ The Amazon EKS Capability for Argo CD now accepts a standard argocd-cm ConfigMap in your cluster to enable custom configuration. This managed GitOps continuous delivery experience can be tuned to your team’s workflows, including custom health checks for Custom Resources, UI banner content, and resource watch/compare behavior. AWS applies settings configured the same way as upstream Argo CD, and built-in health checks for AWS Controllers for Kubernetes (ACK) and kro resources are included.
read more β†’

Amazon EKS adds automated CA rotation lifecycle

πŸ” Amazon Elastic Kubernetes Service (Amazon EKS) now supports managed certificate authority (CA) rotation with automated safeguards. Amazon EKS will manage the rotation lifecycle and update AWS-managed components to trust the successor CA, while customers must replace worker nodes and update external clients to trust the new CA. Features include advance expiration notifications, automatic successor CA appending and activation, and rollback capability. The feature is available at no additional cost in all commercial AWS Regions and can be managed via CLI, APIs, CloudFormation, and the AWS console.
read more β†’

Amazon EKS adds control plane configuration options

πŸ”§ Amazon Elastic Kubernetes Service (Amazon EKS) now lets administrators configure control plane parameters for the scheduler, controller manager, and API server. This capability enables tuning of pod placement strategies, horizontal pod autoscaler responsiveness, and resource lifecycle settings such as event retention. Cluster operators can choose different scheduler fit strategies (for example, MostAllocated or LeastAllocated) to prioritize density or headroom. These control plane configuration options are available in any AWS Region where Amazon EKS is offered.
read more β†’

EKS Provisioned Control Plane Speeds Pod Autoscaling

βš™οΈ Amazon EKS Provisioned Control Plane increases Horizontal Pod Autoscaler (HPA) sync concurrency up to 40Γ— the default Kubernetes value, enabling faster scaling for HPA-driven workloads. This reduces the latency between increased demand and pod scale-out across clusters with many HPA objects. The change is applied for all Provisioned Control Plane customers with no configuration required. It enhances responsiveness for clusters operating at large scale.
read more β†’

Amazon EKS adds PrivateLink for OIDC endpoints

πŸ”’ Amazon EKS now supports AWS PrivateLink for the cluster OIDC discovery and JWKS endpoint, allowing access to the OIDC endpoint used by IAM Roles for Service Accounts (IRSA) privately from your VPC without internet egress. Tools such as eksctl, Terraform, or custom token validators can reach the discovery document and JWKS via an interface VPC endpoint for the com.amazonaws..oidc-eks service. This ensures correct DNS resolution when the EKS management VPC endpoint uses private DNS. The feature is available in all Regions where Amazon EKS is offered at standard AWS PrivateLink pricing.
read more β†’

EKS adds EFA and EC2 placement group support

πŸš€ Amazon EKS now supports Amazon EC2 placement groups and Elastic Fabric Adapter (EFA) configuration for node pools in EKS Auto Mode and the open-source Karpenter. These options let you choose EFA-only or standard ENI configurations on EFA-capable instances and control instance distribution with cluster, spread, or partition placement strategies. The features improve performance and availability for distributed training, inference, and production services and are available in all Regions where EKS operates.
read more β†’