EKS cluster logging disabled

Send EKS control plane logs to CloudWatch.

Description

EKS control plane logs help investigate cluster administration, authentication, and control-component behavior. Application logs alone do not provide all of this information.

Potential impact

Without control plane logs, tracing administrative actions and the causes of failures is harder.

Remediation

Set enabled_cluster_log_types to include api, audit, authenticator, controllerManager, and scheduler. Configure CloudWatch log retention and access permissions.

Examples

The examples show only control plane logging settings. The required IAM role and VPC configuration are omitted.

Before

hcl
resource "aws_eks_cluster" "example" {
  depends_on = [aws_cloudwatch_log_group.example]
  name       = var.cluster_name
}

After

hcl
resource "aws_eks_cluster" "example" {
  depends_on = [aws_cloudwatch_log_group.example]

  enabled_cluster_log_types = ["api", "audit", "authenticator", "controllerManager", "scheduler"]
  name                      = var.cluster_name
}

References