Deep dive into the new Amazon EKS Cluster Access Management features
ID: 301ab4b1-32e7-5054-a180-028238eb1662
STIX ID: report--301ab4b1-32e7-5054-a180-028238eb1662
Feed Name: Datadog Security Labs
This report explains AWS’s new EKS Cluster Access Management, introducing access entries and AWS-managed Kubernetes access policies that can be applied at cluster or namespace scope, and clarifying how these interact with authentication modes (CONFIG_MAP, API_AND_CONFIG_MAP, API). It provides guidance for migrating from the aws-auth ConfigMap (which AWS plans to deprecate), outlines administrative controls including visibility and removal of “shadow administrators,” and offers detection opportunities using CloudTrail events (Create/UpdateAccessEntry and AssociateAccessPolicy) to flag privilege assignments, multi-cluster access grants by a single principal, and cross-account access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
