Main areas covered
| Section | Area | Description |
|---|---|---|
| 2 | Control plane configuration | Control plane logging, KMS encryption for secrets, and restrictions on public API endpoint access |
| 3 | Worker nodes | IMDSv2 for EC2 nodes and restrictions on node-group remote access |
| 4 | Policies | Least-privilege RBAC, namespace isolation, disabling automatic token mounts for the default ServiceAccount, and NetworkPolicy |
| 5 | Managed services | ECR image scanning and KMS encryption for Secrets Manager |