< ciso
brief />
Tag Banner

All news with #aws eks tag

62 articles

Amazon EKS Argo CD now supports custom configuration

๐Ÿ”ง The Amazon EKS Capability for Argo CD now accepts a standard argocd-cm ConfigMap in your cluster to enable custom configuration. This managed GitOps continuous delivery experience can be tuned to your teamโ€™s workflows, including custom health checks for Custom Resources, UI banner content, and resource watch/compare behavior. AWS applies settings configured the same way as upstream Argo CD, and built-in health checks for AWS Controllers for Kubernetes (ACK) and kro resources are included.
read more โ†’

Amazon EKS adds automated CA rotation lifecycle

๐Ÿ” Amazon Elastic Kubernetes Service (Amazon EKS) now supports managed certificate authority (CA) rotation with automated safeguards. Amazon EKS will manage the rotation lifecycle and update AWS-managed components to trust the successor CA, while customers must replace worker nodes and update external clients to trust the new CA. Features include advance expiration notifications, automatic successor CA appending and activation, and rollback capability. The feature is available at no additional cost in all commercial AWS Regions and can be managed via CLI, APIs, CloudFormation, and the AWS console.
read more โ†’

Amazon EKS adds control plane configuration options

๐Ÿ”ง Amazon Elastic Kubernetes Service (Amazon EKS) now lets administrators configure control plane parameters for the scheduler, controller manager, and API server. This capability enables tuning of pod placement strategies, horizontal pod autoscaler responsiveness, and resource lifecycle settings such as event retention. Cluster operators can choose different scheduler fit strategies (for example, MostAllocated or LeastAllocated) to prioritize density or headroom. These control plane configuration options are available in any AWS Region where Amazon EKS is offered.
read more โ†’

EKS Provisioned Control Plane Speeds Pod Autoscaling

โš™๏ธ Amazon EKS Provisioned Control Plane increases Horizontal Pod Autoscaler (HPA) sync concurrency up to 40ร— the default Kubernetes value, enabling faster scaling for HPA-driven workloads. This reduces the latency between increased demand and pod scale-out across clusters with many HPA objects. The change is applied for all Provisioned Control Plane customers with no configuration required. It enhances responsiveness for clusters operating at large scale.
read more โ†’

Amazon EKS adds PrivateLink for OIDC endpoints

๐Ÿ”’ Amazon EKS now supports AWS PrivateLink for the cluster OIDC discovery and JWKS endpoint, allowing access to the OIDC endpoint used by IAM Roles for Service Accounts (IRSA) privately from your VPC without internet egress. Tools such as eksctl, Terraform, or custom token validators can reach the discovery document and JWKS via an interface VPC endpoint for the com.amazonaws..oidc-eks service. This ensures correct DNS resolution when the EKS management VPC endpoint uses private DNS. The feature is available in all Regions where Amazon EKS is offered at standard AWS PrivateLink pricing.
read more โ†’

EKS adds EFA and EC2 placement group support

๐Ÿš€ Amazon EKS now supports Amazon EC2 placement groups and Elastic Fabric Adapter (EFA) configuration for node pools in EKS Auto Mode and the open-source Karpenter. These options let you choose EFA-only or standard ENI configurations on EFA-capable instances and control instance distribution with cluster, spread, or partition placement strategies. The features improve performance and availability for distributed training, inference, and production services and are available in all Regions where EKS operates.
read more โ†’

EMR on EKS Adds Spark Troubleshooting Agent

๐Ÿ› ๏ธ Amazon EMR on EKS now integrates an Apache Spark troubleshooting agent that provides automated root cause analysis and PySpark recommendations through natural language, simplifying diagnosis of job failures. The agent inspects Spark History Server data, executor logs, and cluster configs to detect issues like memory errors, data skew, resource contention, and connectivity problems. Accessible via a "Troubleshoot with AI" option in the EMR on EKS console and via MCP with compatible AI coding agents, the feature is read-only, IAM-authenticated, logged in CloudTrail, and available in Regions with SageMaker Unified Studio.
read more โ†’

EKS Auto Mode adds ARC zonal shift support

๐Ÿ›ก๏ธ Amazon EKS Auto Mode now integrates with Amazon Application Recovery Controller (ARC) to provide zonal shift and autoshift support for clusters using EKS Auto Mode. This feature automatically protects compute during an ARC-initiated zonal shift by stopping new capacity provisioning and preventing voluntary disruptions in the impaired zone. Enable ARC zonal shift on your cluster to use this capability, which is available in all Regions where EKS Auto Mode is offered.
read more โ†’

AWS Neuron 2.31.0 adds NKI 0.5.0 and UltraServer

๐Ÿš€ AWS released Neuron 2.31.0, introducing NKI 0.5.0 with MX FP8 scale dtype, tensor indirection for indexed access patterns, and zero-cost NkiTensor view APIs. The release also brings the Neuron UltraServer Operator for Amazon EKS in public beta to automate UltraServer discovery and workload claims for Trainium UltraServer workloads. The Neuron Compiler now uses a redesigned codegen backend enabled by default on Trn2 and Trn3 for improved performance, while Runtime and Explorer add usability and debugging improvements.
read more โ†’

AWS reduces EKS Auto Mode GPU management fees

๐Ÿ”” Amazon EKS Auto Mode now reduces management fees for GPU and accelerated instance types, effective July 1, 2026. G-series Auto Mode fees drop 35%, while P-series and AWS Trainium fees drop 60%, applied automatically to existing clusters. EKS Auto Mode includes accelerator-focused features like parallel image pulling and accelerator-aware node repair to speed startup and improve reliability for ML and rendering workloads. The pricing change applies in all Regions where EKS Auto Mode is available and mirrors identical reductions for ECS Managed Instances.
read more โ†’

SageMaker HyperPod adds AMI versioning and auto-patch

๐Ÿ› ๏ธ Amazon SageMaker HyperPod now reports AMI versions across clusters and can automatically apply backward-compatible security patches without disrupting workloads. Administrators can view AMI semantic versions (major.minor.patch), detect drift, and roll back to prior versions โ€” preserving NVIDIA drivers, CUDA, and other bundled software โ€” via the UpdateClusterSoftware API. Auto-patching is opt-in per instance group, applies only when nodes are idle, and avoids major/minor upgrades; it can be enabled through CreateCluster or UpdateCluster APIs. A new AMI support policy defines patch support timelines; both features are available for EKS-orchestrated HyperPod clusters in supported Regions.
read more โ†’

GuardDuty Runtime adds sensitive file modification detection

๐Ÿ›ก๏ธ Amazon GuardDuty Runtime Monitoring now includes three new threat detections to alert teams when sensitive files are modified on Amazon EC2 instances and container workloads on Amazon EKS and Amazon ECS. These findings monitor critical system files such as configuration files, authentication settings, and system logs to surface post-compromise activity. The detections map to MITRE ATT&CKยฎ tactics and provide remediation guidance while using correlation analysis to reduce false positives. The capability is available to customers with GuardDuty Runtime Monitoring enabled, with a 30-day trial for new users.
read more โ†’

Amazon EKS adds Kubernetes version rollback support

๐Ÿ”ง Amazon Elastic Kubernetes Service (Amazon EKS) now supports Kubernetes minor version rollback, letting you revert to the prior minor version within 7 days if an upgrade causes issues. You can start a rollback via the Amazon EKS console, AWS CLI, or AWS SDKs, and EKS evaluates cluster rollback readiness with automated checks for API compatibility, version skew, add-on compatibility, and cluster health. For clusters using EKS Auto Mode, worker nodes are automatically managed during rollback to respect configured disruption controls, and the feature is available at no additional cost in all AWS Regions where EKS is offered.
read more โ†’

AWS Workload Credentials Provider: Role Chaining and Prefetch

๐Ÿ”’ This post explains how to use two enhancements to the AWS Workload Credentials Provider: role chaining for cross-account secret retrieval and prefetching to reduce cold-start latency. It covers configuration, required IAM permissions, SSRF token usage, and how to build and deploy the Rust-based provider across EC2, ECS, EKS, and Lambda. Examples show curl and Python calls, TOML configuration for max roles, and prefetch settings for individual secrets or tag-based discovery.
read more โ†’

June 2026 Threat Technique Catalog Update for AWS

๐Ÿ›ก๏ธ The AWS CIRT updated the Threat Technique Catalog for June 2026, adding five new entries focused on container security, organization-level trust, and compute hijacking. The update documents EKS workload modification, exploitation of public-facing Kubernetes services, sts:AssumeRoot abuse across AWS Organizations, compute hijacking in clusters, and account invitations into attacker-controlled organizations. It also refreshes three existing entries with expanded detection and mitigation guidance.
read more โ†’

CloudWatch OTel Container Insights for Amazon EKS

๐Ÿš€ Amazon CloudWatch now offers OTel Container Insights for Amazon EKS, collecting infrastructure metrics at 30-second granularity using open-source receivers like cAdvisor, Kube State Metrics, and NVIDIA DCGM. Each metric includes OpenTelemetry semantic conventions and Kubernetes labels to simplify correlation across nodes, pods, and workloads with a single PromQL query. Pre-built dashboards provide immediate visibility into cluster health, node performance, and pod-level resource usage, and the CloudWatch PromQL endpoint enables direct connection of existing Prometheus and Grafana dashboards. Enable the feature from the EKS console, the CloudWatch Observability add-on (v6.2.0+), Helm, or CloudFormation; it is available in all commercial AWS Regions except UAE, Bahrain, and Israel (Tel Aviv).
read more โ†’

Amazon EKS adds customer-routed control plane egress

๐Ÿ” Amazon EKS now supports customer-routed control plane egress, allowing outbound Kubernetes API server traffic to traverse your Amazon VPC. This includes admission webhook callbacks, OpenID Connect (OIDC) provider lookups, and aggregate API server requests. By routing through your VPC you can manage routing, security groups, and egress paths to meet data perimeter and compliance needs. Enable the feature by setting controlPlaneEgressMode to CUSTOMER_ROUTED and enforce it org-wide with the eks:controlPlaneEgressMode IAM condition key.
read more โ†’

EKS local clusters now support EC2 instance store on Outposts

๐Ÿ†• AWS now supports Amazon EKS local clusters on first- and second-generation AWS Outposts racks that boot Amazon EC2 instances from EC2 instance store. This extends Outpostsโ€™ static stability benefits to EKS local clusters, keeping the entire Kubernetes control plane on the Outpost to meet data residency needs and reduce impact from temporary network disconnects. The updated architecture brings greater operational parity with cloud EKS, includes managed control plane responsibilities, and adds support for EKS add-ons and modern auth mechanisms.
read more โ†’

CloudWatch Application Signals adds health-ranked insights

๐Ÿ› ๏ธ Amazon CloudWatch Application Signals now ranks service health on the application map and adds new infrastructure, logs, and traces tabs on the service overview page, enabling operators to triage unhealthy services and inspect compute, log snippets, and trace details in one place. These features surface runtime indicators for Amazon EKS, Amazon ECS, AWS Lambda, and Amazon EC2, and provide curated metrics with deep links to relevant monitoring tools to speed root-cause analysis. The capabilities are available in all Regions that support Application Signals.
read more โ†’

AWS Backup for Amazon EKS in Germany Region

๐Ÿ”’ AWS Backup now supports Amazon EKS in the AWS European Sovereign Cloud (Germany) Region, providing fully managed, policy-driven data protection and recovery for EKS clusters. The service includes automated scheduling, retention management, immutable vaults, and cross-Region and cross-account copies. Customers can protect entire clusters, namespaces, or individual persistent volumes without agents, replacing custom scripts or third-party tools.
read more โ†’