Insufficient restrictions on EKS node group remote access

Restrict EKS node management ports to the security groups used by approved management hosts.

Description

When creating an EKS managed node group, specifying RemoteAccess.Ec2SshKey without SourceSecurityGroups opens the management port to 0.0.0.0/0. This is SSH port 22 for Linux nodes or RDP port 3389 for Windows nodes. Actual internet reachability also requires suitable addresses, routes, and other network conditions.

Allow direct remote access to operational nodes only when needed. Restricting the network source does not replace operating system authentication or node and cluster permissions.

Potential impact

  • Reachable management ports can become targets for external scans or authentication attacks.
  • A compromised node can affect workloads or the cluster according to the data, credentials, and permissions available on that node.

Remediation

  • If remote access is required, set SourceSecurityGroups to approved management groups and attach the actual management hosts to those groups.
  • If direct access is unnecessary, remove remote access configuration and consider management through Session Manager with the required agent, IAM permissions, and connectivity.
  • CloudFormation changes to remote access properties require node group replacement. Plan workload capacity and migration, and test the resulting access restrictions.

Examples

Supply actual cluster, node role, subnet, and VpcId values. The value in Ec2SshKey: ED25519 must be the name of an existing EC2 key pair, not an algorithm selection.

Before

yaml
Resources:
  EKSNodegroup:
    Type: AWS::EKS::Nodegroup
    Properties:
      ClusterName: prod
      NodeRole: arn:aws:iam::012345678910:role/eksInstanceRole
      Subnets:
        - subnet-6782e71e
      RemoteAccess:
        Ec2SshKey: ED25519

Only the key pair is specified; management access is not restricted by a source security group.

After

yaml
Resources:
  SSHAccessToNodeSG:
    Type: AWS::EC2::SecurityGroup
    Properties:
      VpcId: !Ref VpcId
      GroupDescription: ssh access to eks workers

  EKSNodegroup:
    Type: AWS::EKS::Nodegroup
    Properties:
      ClusterName: prod
      NodeRole: arn:aws:iam::012345678910:role/eksInstanceRole
      Subnets:
        - subnet-6782e71e
      RemoteAccess:
        Ec2SshKey: ED25519
        SourceSecurityGroups:
          - !Ref SSHAccessToNodeSG

Access is restricted to management hosts using the specified group. Creating the group does not attach any hosts to it; prepare those associations and the network path separately.

References