Description
When an EKS managed node group is created with an EC2 SSH key but no source security groups, the management port is opened to 0.0.0.0/0: SSH port 22 for Linux or RDP port 3389 for Windows. Actual connectivity also depends on addressing, routes, and other network configuration.
Remote access is not inherently unsafe, but its permitted scope should be explicit.
Potential impact
- Wider management-port exposure: remote access to nodes can be broader than necessary.
- Weaker operational access control: it becomes harder to limit connections to approved management hosts.
- A larger attack surface: externally reachable nodes can receive authentication attempts and vulnerability probes.
Remediation
- Set
remote_access.source_security_group_idsto the security group IDs used by approved management hosts. - Consider removing remote access when it is unnecessary.
- Configure the IAM permissions and connectivity required for alternatives such as a bastion or SSM Session Manager, and check whether the change plan includes node replacement.
Examples
These are remote-access excerpts. Provide the referenced resources, scaling settings, and an existing EC2 key pair separately. The management security group in the after example must be attached to approved management hosts.
Before
resource "aws_eks_node_group" "example" {
cluster_name = aws_eks_cluster.example.name
node_group_name = "example"
node_role_arn = aws_iam_role.example.arn
subnet_ids = aws_subnet.example[*].id
remote_access {
ec2_ssh_key = "my-rsa-key"
}
}
After
resource "aws_eks_node_group" "example" {
cluster_name = aws_eks_cluster.example.name
node_group_name = "example"
node_role_arn = aws_iam_role.example.arn
subnet_ids = aws_subnet.example[*].id
remote_access {
ec2_ssh_key = "my-rsa-key"
source_security_group_ids = [aws_security_group.management.id]
}
}
Before the change, only a key is specified and the management-port source is not restricted. Afterward, a list of management-host security group IDs is specified. Verify the actual host connections and other security group rules too.