EKS public access CIDRs allow the entire internet

Even when public EKS access is required, keep allowed CIDR ranges as narrow as necessary.

Description

Allowing 0.0.0.0/0 on an EKS public API endpoint lets every IPv4 address attempt a connection. Authentication and Kubernetes authorization still apply, but management IP ranges should be restricted even when public access is required.

Allowing all sources increases exposure to unnecessary authentication attempts and scanning.

Potential impact

  • Broad control-plane exposure: sources across the internet can attempt to access the cluster endpoint.
  • More attack attempts: the endpoint can attract brute-force attempts, vulnerability probing, and automated scans.
  • Operational risk: compromised credentials can be misused without a source-network restriction.

Remediation

  • Restrict public_access_cidrs to the actual outbound IP ranges of approved administrators or clients.
  • If nodes do not use a private endpoint, include the outbound addresses of the nodes or their NAT gateway. Test node and administrative connections before applying the restriction.
  • If public access is unnecessary, prepare the private endpoint and connectivity before switching to endpoint_public_access = false.

Examples

Define the referenced role and subnets separately. The after example uses the documentation address 203.0.113.10/32; replace it with approved management addresses and any required node outbound addresses.

Before

hcl
resource "aws_eks_cluster" "example" {
  name     = "example"
  role_arn = aws_iam_role.example.arn

  vpc_config {
    subnet_ids             = [aws_subnet.example1.id, aws_subnet.example2.id]
    endpoint_public_access = true
    public_access_cidrs    = ["0.0.0.0/0"]
  }
}

After

hcl
resource "aws_eks_cluster" "example" {
  name     = "example"
  role_arn = aws_iam_role.example.arn

  vpc_config {
    subnet_ids             = [aws_subnet.example1.id, aws_subnet.example2.id]
    endpoint_public_access = true
    public_access_cidrs    = ["203.0.113.10/32"]
  }
}

Before the change, the public API allows all IPv4 sources. Afterward, the range is limited to the specified address. CIDR restrictions do not replace authentication or authorization and do not control access to the private endpoint.

References