EKS node remote access has no source security groups

When enabling remote access to an EKS node group, also restrict the security groups allowed to connect.

Description

When an EKS managed node group is created with an EC2 SSH key but no source security groups, the management port is opened to 0.0.0.0/0: SSH port 22 for Linux or RDP port 3389 for Windows. Actual connectivity also depends on addressing, routes, and other network configuration.

Remote access is not inherently unsafe, but its permitted scope should be explicit.

Potential impact

  • Wider management-port exposure: remote access to nodes can be broader than necessary.
  • Weaker operational access control: it becomes harder to limit connections to approved management hosts.
  • A larger attack surface: externally reachable nodes can receive authentication attempts and vulnerability probes.

Remediation

  • Set remote_access.source_security_group_ids to the security group IDs used by approved management hosts.
  • Consider removing remote access when it is unnecessary.
  • Configure the IAM permissions and connectivity required for alternatives such as a bastion or SSM Session Manager, and check whether the change plan includes node replacement.

Examples

These are remote-access excerpts. Provide the referenced resources, scaling settings, and an existing EC2 key pair separately. The management security group in the after example must be attached to approved management hosts.

Before

hcl
resource "aws_eks_node_group" "example" {
  cluster_name    = aws_eks_cluster.example.name
  node_group_name = "example"
  node_role_arn   = aws_iam_role.example.arn
  subnet_ids      = aws_subnet.example[*].id

  remote_access {
    ec2_ssh_key = "my-rsa-key"
  }
}

After

hcl
resource "aws_eks_node_group" "example" {
  cluster_name    = aws_eks_cluster.example.name
  node_group_name = "example"
  node_role_arn   = aws_iam_role.example.arn
  subnet_ids      = aws_subnet.example[*].id

  remote_access {
    ec2_ssh_key                = "my-rsa-key"
    source_security_group_ids = [aws_security_group.management.id]
  }
}

Before the change, only a key is specified and the management-port source is not restricted. Afterward, a list of management-host security group IDs is specified. Verify the actual host connections and other security group rules too.

References