logo

Deep dive into the new Amazon EKS Cluster Access Management features

ID: 301ab4b1-32e7-5054-a180-028238eb1662

STIX ID: report--301ab4b1-32e7-5054-a180-028238eb1662

Feed Name: Datadog Security Labs

Date Published: 2023-12-19

Date Updated: 2026-04-27

...
...

This report explains AWS’s new EKS Cluster Access Management, introducing access entries and AWS-managed Kubernetes access policies that can be applied at cluster or namespace scope, and clarifying how these interact with authentication modes (CONFIG_MAP, API_AND_CONFIG_MAP, API). It provides guidance for migrating from the aws-auth ConfigMap (which AWS plans to deprecate), outlines administrative controls including visibility and removal of “shadow administrators,” and offers detection opportunities using CloudTrail events (Create/UpdateAccessEntry and AssociateAccessPolicy) to flag privilege assignments, multi-cluster access grants by a single principal, and cross-account access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.