Public access enabled for an EKS cluster

Review the need for public EKS API access and use a private management path when public access is unnecessary.

Description

An EKS public Kubernetes API endpoint is a management endpoint reachable from permitted external networks. Public access CIDRs determine the allowed sources; IAM authentication and Kubernetes authorization still apply to a public endpoint.

The EKS control plane manages the entire cluster. Unnecessarily broad public access increases the range of sources that can scan it or attempt access.

Potential impact

  • Control-plane exposure: permitted external sources can attempt to access the Kubernetes API server.
  • A larger attack surface: the endpoint can attract authentication attempts and vulnerability probing.
  • Weaker operational isolation: administration depends on public access policies instead of a private management path.

Remediation

  • If public access is unnecessary, configure endpoint_private_access = true and set endpoint_public_access = false.
  • Before switching, verify that nodes and administrators can reach the API from the VPC or a connected management network through the required DNS, routes, and security groups.
  • If public access is required, restrict CIDRs to approved sources and manage authentication and authorization alongside network access.

Examples

These are excerpts of API access settings. Define the referenced IAM role and subnets separately and prepare the actual management connection.

Before

hcl
resource "aws_eks_cluster" "example" {
  name     = "example"
  role_arn = aws_iam_role.example.arn

  vpc_config {
    subnet_ids             = [aws_subnet.example1.id, aws_subnet.example2.id]
    endpoint_public_access = true
  }
}

After

hcl
resource "aws_eks_cluster" "example" {
  name     = "example"
  role_arn = aws_iam_role.example.arn

  vpc_config {
    subnet_ids             = [aws_subnet.example1.id, aws_subnet.example2.id]
    endpoint_public_access = false
    endpoint_private_access = true
  }
}

Before the change, public API access is enabled. Afterward, the private endpoint is enabled and public access is disabled. Verify required node and administrative connections first; private access still requires appropriate authentication and authorization.

References