Description
When creating an EKS managed node group, specifying RemoteAccess.Ec2SshKey without SourceSecurityGroups opens the management port to 0.0.0.0/0. This is SSH port 22 for Linux nodes or RDP port 3389 for Windows nodes. Actual internet reachability also requires suitable addresses, routes, and other network conditions.
Allow direct remote access to operational nodes only when needed. Restricting the network source does not replace operating system authentication or node and cluster permissions.
Potential impact
- Reachable management ports can become targets for external scans or authentication attacks.
- A compromised node can affect workloads or the cluster according to the data, credentials, and permissions available on that node.
Remediation
- If remote access is required, set
SourceSecurityGroupsto approved management groups and attach the actual management hosts to those groups. - If direct access is unnecessary, remove remote access configuration and consider management through Session Manager with the required agent, IAM permissions, and connectivity.
- CloudFormation changes to remote access properties require node group replacement. Plan workload capacity and migration, and test the resulting access restrictions.
Examples
Supply actual cluster, node role, subnet, and VpcId values. The value in Ec2SshKey: ED25519 must be the name of an existing EC2 key pair, not an algorithm selection.
Before
Resources:
EKSNodegroup:
Type: AWS::EKS::Nodegroup
Properties:
ClusterName: prod
NodeRole: arn:aws:iam::012345678910:role/eksInstanceRole
Subnets:
- subnet-6782e71e
RemoteAccess:
Ec2SshKey: ED25519
Only the key pair is specified; management access is not restricted by a source security group.
After
Resources:
SSHAccessToNodeSG:
Type: AWS::EC2::SecurityGroup
Properties:
VpcId: !Ref VpcId
GroupDescription: ssh access to eks workers
EKSNodegroup:
Type: AWS::EKS::Nodegroup
Properties:
ClusterName: prod
NodeRole: arn:aws:iam::012345678910:role/eksInstanceRole
Subnets:
- subnet-6782e71e
RemoteAccess:
Ec2SshKey: ED25519
SourceSecurityGroups:
- !Ref SSHAccessToNodeSG
Access is restricted to management hosts using the specified group. Creating the group does not attach any hosts to it; prepare those associations and the network path separately.