Description
Allowing 0.0.0.0/0 on an EKS public API endpoint lets every IPv4 address attempt a connection. Authentication and Kubernetes authorization still apply, but management IP ranges should be restricted even when public access is required.
Allowing all sources increases exposure to unnecessary authentication attempts and scanning.
Potential impact
- Broad control-plane exposure: sources across the internet can attempt to access the cluster endpoint.
- More attack attempts: the endpoint can attract brute-force attempts, vulnerability probing, and automated scans.
- Operational risk: compromised credentials can be misused without a source-network restriction.
Remediation
- Restrict
public_access_cidrsto the actual outbound IP ranges of approved administrators or clients. - If nodes do not use a private endpoint, include the outbound addresses of the nodes or their NAT gateway. Test node and administrative connections before applying the restriction.
- If public access is unnecessary, prepare the private endpoint and connectivity before switching to
endpoint_public_access = false.
Examples
Define the referenced role and subnets separately. The after example uses the documentation address 203.0.113.10/32; replace it with approved management addresses and any required node outbound addresses.
Before
resource "aws_eks_cluster" "example" {
name = "example"
role_arn = aws_iam_role.example.arn
vpc_config {
subnet_ids = [aws_subnet.example1.id, aws_subnet.example2.id]
endpoint_public_access = true
public_access_cidrs = ["0.0.0.0/0"]
}
}
After
resource "aws_eks_cluster" "example" {
name = "example"
role_arn = aws_iam_role.example.arn
vpc_config {
subnet_ids = [aws_subnet.example1.id, aws_subnet.example2.id]
endpoint_public_access = true
public_access_cidrs = ["203.0.113.10/32"]
}
}
Before the change, the public API allows all IPv4 sources. Afterward, the range is limited to the specified address. CIDR restrictions do not replace authentication or authorization and do not control access to the private endpoint.