
Secure your Kubernetes on AWS with practical, hands-on ECS security guidance built for professionals. Learn from real-world use cases, diagrams, and live demos to gain immediate security confidence.
Learn how the Kubernetes API server authenticates using webhook token authentication with AWS IAM, or OIDC, and service account tokens, then enforces authorization with the AWS auth ConfigMap and RBAC.
Deploy an EKS cluster using a CloudFormation template, configuring VPC networking, security groups, IAM roles, a node group, and AWS auth configmap to enable worker nodes and cluster access.
learn to manage eks authentication and authorization with eksctl, update the aws auth configmap by mapping iam roles to Kubernetes users and groups, and enforce least privilege via rbac.
Learn to add an IAM user to an EKS cluster, assign permissions, update the AWS auth ConfigMap, and verify access with kubectl.
Apply least privilege access in AWS EKS by creating restricted cluster roles and bindings that limit a user to the default namespace while enabling view across namespaces.
Create and use an IAM role to access the EKS cluster, map it to a group via IAM identity mapping, and switch roles to apply restricted permissions with less effort.
Explore cluster access manager to simplify aws iam access to eks clusters by using access entries and policies, and choose from configmap, api and configmap, or api modes.
Remove admin privileges from cluster creators to enforce least privilege; create clusters with bootstrap cluster creator admin permissions false flag, then revoke via disassociate access policy or delete access entry.
Learn to use access manager to authenticate users and roles for an EKS cluster, switch authentication modes, and create access entries and map policies to principals via the CLI.
Dissociate the Amazon EKS cluster admin policy from the cluster creator via the CLI, then verify no admin policies remain. Re-enable admin access later through the console for the demos.
Learn how Kubernetes service accounts assign pod identities and how IRSA attaches AWS IAM roles to those accounts, enabling pods to obtain temporary credentials and access AWS services securely.
Discover how service accounts let pods authenticate and receive permissions in Kubernetes, using default and custom accounts with role bindings and the view cluster role. The demo walks through applying manifests, inspecting pods, and verifying permissions in the AWS console.
Demonstrates IRSA by creating an OpenID connect identity provider, defining an IAM policy, and linking a service account to grant a pod access to an S3 bucket.
Block access to EC2 instance metadata to prevent pods inheriting permissions. Enforce IMDSv2 with a hop limit of 1 using AWS EC2 modify instance metadata options and update Terraform templates.
Apply best practices to restrict bots on EC2 worker nodes from accessing instance profiles by disabling access, using IMDS v2, HTTP tokens, and hop limit configuration via CloudFormation.
Scope the IAM role trust policy to a specific Kubernetes service account when enabling pod access to an S3 bucket, ensuring only that service account can assume the role.
Secure an eks iam role by enforcing a strict trust relationship with the OpenID Connect provider, binding it to a specific service account and avoiding wildcards.
Disable auto mounting of service account tokens to reduce attack surface; set automount service account token to false in the pod spec or patch the default service account.
Learn to improve EKS security by disabling the auto mount of service account tokens for pods, using manifest updates or kubectl patch and verification steps.
Assign a dedicated service account to each application with the minimum permissions it needs. This reduces security risks and simplifies troubleshooting by clearly linking actions to the responsible application.
Review cluster access and revoke anonymous or unauthenticated permissions using the rbac lookup tool, kubectl edits, and targeted role bindings to secure the AWS EKS cluster.
Review and revoke anonymous and unauthenticated access in Kubernetes to limit API server exposure. Identify system anonymous and system unauthenticated permissions and bind only necessary roles.
Master pod security in Kubernetes by managing Linux capabilities to prevent overprivileged containers and privilege escalation, and apply policy as code with admission controllers such as OPA, Gatekeeper, and Kavanagh.
Demonstrate policy as code in Kubernetes with Cubano to enforce image source restrictions, test cluster policies, and monitor compliance via policy reports.
Explore Kubernetes pod security with pod security standards and the pod security admission controller, applying privileged, baseline, and restricted policies in enforce, warn, and audit modes at the namespace level.
Use multiple psa modes to gradually roll out policies, starting with warn and audit before enforcing, minimizing disruptions and enabling fine-tuning with policy baseline.
Learn best practices for running containers as non-root by removing shells, using a non-root user in Dockerfiles, and enforcing RunAsUser and RunAsGroup security contexts in Kubernetes to drop privileges.
Configure security context to run containers as non-root users, setting runAsUser and runAsGroup to 1000 in Kubernetes deployments, and enforce this with policy as code.
Enforce read-only hostpath volumes to limit pod access to the host file system, reducing security risks and privilege escalation, while applying pod security standards to restrict directories.
This hands-on demo shows how hostpath volumes can expose the host filesystem, enabling privilege escalation, and demonstrates restricting hostpath to /var/log/nginx with read-only policy enforced by admission webhooks.
Prevent privileged escalation by setting allow privileged escalation to false in the podspec and applying a policy as code mutating policy. Enforce the principle of least privilege.
Learn to disable service discovery in pods by turning off environment variables and DNS exposure, using enable service links false and DNS policy default to reduce exposure of cluster information.
Explore Kubernetes service discovery, enabling pods to find peers without hardcoded endpoints. The demo shows creating a nodeport service, inspecting environment variables, and disabling discovery to reduce leaks.
Set resource requests and limits for containers to guide scheduling and prevent eviction. Understand guaranteed, burstable, and best-effort pods, and use quotas and limit ranges in namespaces to enforce limits.
Create a development namespace and apply a resource quota to cap cpu and memory. Enforce limit ranges to ensure pods get default requests and limits.
Explore soft multi-tenancy in Kubernetes, where multiple teams or SaaS tenants share a cluster using namespaces, quotas, RBAC, and network policies to maintain isolation and security.
Isolate tenant pods by dedicating nodes or using Fargate, then enforce node affinity, taints, and tolerations, and reinforce isolation with policy-based controls via admission controllers and OPA.
Enforce security policies in multi-tenant Kubernetes environments using admission controllers, with Open Policy Agent and Gatekeeper to isolate namespaces, govern pod security, and generate default network policies.
Isolate pods to dedicated nodes using Kubernetes node affinity, taints, and tolerations across tenant namespaces, while Cubano automates these policies.
Evaluate hard multi-tenancy in EKS: use dedicated clusters per tenant for strong isolation, security, and compliance, while noting high costs, limited resource sharing, and increased management overhead.
Discover detective controls that detect and respond to security incidents in AKS clusters through log monitoring and analysis, gaining visibility into the control plane, nodes, pods, and AWS resources.
Enable control plane logs for your AWS EKS cluster to monitor API server, scheduler, controller manager, authenticator, and audit activity via CloudWatch, using CLI or IaC to ensure production readiness.
Enable and analyze EKS control plane logs using the CLI and CloudWatch, covering API server, audit, authenticator, controller manager, and scheduler; use Logs Insights to run queries.
Analyze logs with Log Insights in Amazon CloudWatch using SQL-like queries. Visualize results with charts and dashboards and filter by fields like message, timestamp, ingestion time, log stream, and log.
Monitor for suspicious events in your amazon ecs logs using cloudwatch metric filters and alarms, trigger sns notifications or lambda-based remediation, and test thresholds to ensure reliable detection.
Set up CloudWatch alarms to monitor ECS cluster logs, filter for 403 forbidden and 401 unauthorized responses, alert via SNS, test metric filters, and simulate AWS auth Configmap changes.
Audit CloudTrail logs to gain visibility into Eks cluster activities, detect security incidents, and monitor service accounts and iam roles for access control changes, creation, and scaling.
Use CloudTrail to audit API calls in an EKS cluster, review trails and event history, and inspect S3 logs to detect cluster creation, config changes, and service account activity.
Use CloudTrail insights to establish a baseline of management events and flag unusual activity with insights events. Enable insights via console or CLI to monitor call volume and detect spikes.
GuardDuty monitors EKS audit logs to detect unusual activity using machine learning and threat intelligence, translating findings into actionable alerts that integrate with Detective, Security Hub, and EventBridge.
Enable GuardDuty to monitor your EKS cluster and detect suspicious activity, view findings by severity, and export results to EventBridge and S3 for analysis during the 30-day free trial.
Secure pod communication in the EKS cluster with network policies that enforce a default deny, control ingress and egress, and isolate pods by labels and namespaces, using VPC CNI.
Apply a default deny policy to establish a secure baseline that blocks all traffic, then allow essential traffic like DNS queries via egress and ingress rules to support least privilege.
Regularly review and update network policies to match application needs and infrastructure changes. Monitor traffic and audit for least-privilege violations with EKS audit logs and open policy agent.
Learn to enforce pod-to-pod network isolation in AWS EKS by creating and testing network policies, applying security best practices with deny all, namespace-based, and client-specific rules, plus egress controls.
Explore how security groups govern traffic in EKS, including node and pod security groups, default and restricted rules, and linking pods to groups via selectors.
Compare Kubernetes network policies and AWS security groups to control traffic; network policies offer pod-level control with labels, security groups handle external access; use them together for defense in depth.
Deploy and secure an AWS EKS cluster using CloudFormation; configure pod security groups, enable the CNI for pods, and connect a green pod to an RDS MySQL instance.
Learn how to create and use security groups for pods in an EKS cluster, configure RDS access with secrets and environment variables, and verify connectivity against a red pod.
Learn encryption in transit in Kubernetes, securing inter-node and service traffic with TLS. Discover how AWS nitro instances enable inter-node encryption and how to deploy and manage a service mesh.
Explore Istio, a widely adopted open source service mesh for Kubernetes, and see how sidecar envoy proxies enable mutual TLS, identity management, and observability without changing application code.
Explore encryption in transit by terminating tls at various kubernetes points—load balancer, ingress, pods, or mutual tls between pods—using cert-manager and sto service mesh to meet security and regulatory requirements.
Terminate TLS at the load balancer using ACM certificates and the ALB annotation, port 443, with an http backend; traffic inside the EKS cluster remains unencrypted unless TLS is re-enabled.
Terminate https traffic at the network load balancer with an AWS certificate and Route 53 DNS, deploy via a single manifest, and verify end-to-end secure access to nginx.
Enable tls and mtls for kubernetes workloads with acm private ca and cert manager to issue certs stored as secrets for ingress and pods, enabling management and hsm-based key protection.
Learn to terminate encrypted ingress traffic using AWS Private Certificate Authority and cert-manager, wiring an nginx ingress behind a network load balancer and using ACM Private Certificate Authority certificates.
Set up a Kubernetes app behind an nginx ingress, terminate tls with a private acm ca, create a short-lived rsa cert, and map a dns record with Route 53.
Explore data encryption at rest and secrets management for securing Kubernetes clusters on ECS, and compare storage services such as EBS, EFS, and FSX for Lustre.
Enable encryption at rest for EBS, EFS, and FSX Lustre via AWS managed keys or CMKs in KMS, and provision encrypted volumes with CSI drivers and storage classes.
Rotate customer managed keys periodically to improve security and meet PCI, DSS, and high PA compliance, while AWS KMS automates rotation and preserves previous key versions.
Explore how Kubernetes secrets store passwords, tokens, and keys in etcd with base64 encoding, and inject them into pods as environment variables or mounted volumes through the API server.
Use separate namespaces and per-namespace RBAC to isolate secrets by application, simplifying management and auditing. Mount secrets as volumes (tmpfs) to keep credentials in memory and auto-remove with pods.
Explore AWS Secrets Manager practices, including encryption at rest and in transit with KMS, automated rotation, and centralized secret management, and mount secrets in Kubernetes via ASCP and CSI driver.
Secure the host layer as the foundation of an EKS cluster since host vulnerabilities impact containers; implement defense-in-depth across host, container, and application security.
Mount AWS Secrets Manager secrets in an EKS pod using the secrets store CSI driver; install the provider and rotate the secret to verify propagation.
Select a container optimized OS for Kubernetes worker nodes to reduce attack surface. Bottlerocket offers secure boot and SELinux, with an AWS managed EKS optimized AMI as a lightweight alternative.
Keep worker node OS updated to reduce vulnerabilities and meet compliance. Monitor change logs for EKS AMIs and automate rollout with CI/CD or eksctl to drain and replace outdated nodes.
Treat worker nodes as immutable and automate replacements, using auto scaling groups or new node groups, and consider Fargate for automatic updates with multiple pod replicas for stability.
Run kube bench to audit your Kubernetes cluster against CIS benchmarks, strengthening security by identifying misconfigurations and integrating audits with CI/CD and CloudWatch alerts.
Scan EC2 nodes with Amazon Inspector to detect CVEs and exposure. Network exposure checks work without the SSM agent across all EC2 instances to catch misconfigurations.
Conclude the course by reinforcing how to secure your X clusters, and keep practicing to strengthen your Kubernetes security posture.
Welcome!
I’m excited to guide you through securing Amazon EKS in real-world scenarios. This course is designed for professionals who want to strengthen their Kubernetes security skills on AWS with a practical, hands-on approach that covers architecture, configuration, monitoring, and troubleshooting.
WHAT YOU WILL LEARN
Secure Amazon EKS clusters using best practices and AWS-native tools.
Implement authentication, authorization, and network security controls.
Configure pod security, IAM roles for service accounts, and encryption.
Use real-world examples and common security use cases.
Apply security concepts to both development and production environments.
COURSE FORMAT
Hands-on and technical: this is not just theory — you will see live demos.
Includes diagrams, step-by-step guidance, and practical tips.
Based on real-world production experience and security compliance needs.
No exam or certification — just applicable skills you can use immediately to improve your Kubernetes workloads.
REQUIREMENTS
Basic knowledge of Kubernetes and AWS is recommended.
Experience with the AWS Management Console and kubectl will help you follow along faster.
WHO THIS COURSE IS FOR
Cloud engineers, DevOps engineers, and architects working with AWS EKS.
Professionals who want to improve their Kubernetes security posture in AWS environments.
Anyone interested in securing workloads with policies, encryption, and identity management.
By the end of this course, you will have a solid foundation to secure your Amazon EKS clusters and the confidence to apply these techniques in production with best practices, automation, and ongoing improvement.