Description
An EKS public Kubernetes API endpoint is a management endpoint reachable from permitted external networks. Public access CIDRs determine the allowed sources; IAM authentication and Kubernetes authorization still apply to a public endpoint.
The EKS control plane manages the entire cluster. Unnecessarily broad public access increases the range of sources that can scan it or attempt access.
Potential impact
- Control-plane exposure: permitted external sources can attempt to access the Kubernetes API server.
- A larger attack surface: the endpoint can attract authentication attempts and vulnerability probing.
- Weaker operational isolation: administration depends on public access policies instead of a private management path.
Remediation
- If public access is unnecessary, configure
endpoint_private_access = trueand setendpoint_public_access = false. - Before switching, verify that nodes and administrators can reach the API from the VPC or a connected management network through the required DNS, routes, and security groups.
- If public access is required, restrict CIDRs to approved sources and manage authentication and authorization alongside network access.
Examples
These are excerpts of API access settings. Define the referenced IAM role and subnets separately and prepare the actual management connection.
Before
resource "aws_eks_cluster" "example" {
name = "example"
role_arn = aws_iam_role.example.arn
vpc_config {
subnet_ids = [aws_subnet.example1.id, aws_subnet.example2.id]
endpoint_public_access = true
}
}
After
resource "aws_eks_cluster" "example" {
name = "example"
role_arn = aws_iam_role.example.arn
vpc_config {
subnet_ids = [aws_subnet.example1.id, aws_subnet.example2.id]
endpoint_public_access = false
endpoint_private_access = true
}
}
Before the change, public API access is enabled. Afterward, the private endpoint is enabled and public access is disabled. Verify required node and administrative connections first; private access still requires appropriate authentication and authorization.