New EKS Access Management and Pod Identity features: a security analysis
ID: eea90dcb-21c4-5d4d-a4c1-ce407260c400
STIX ID: report--eea90dcb-21c4-5d4d-a4c1-ce407260c400
Feed Name: Wiz Blog
This report analyzes Amazon EKS’s new Pod Identity and access management features, explaining how authentication modes, access entries, and access policies change cloud–cluster identity flows and complicate permission auditing. It details security implications such as token theft and increased attack surface (e.g., pod-identity-agent/DaemonSet), warns against risky defaults like using the default ServiceAccount, and provides best-practice mitigations (least privilege, namespace/node segregation, admission controls, disabling SA token automount). The report also recommends extending detection to include AWS CloudTrail alongside Kubernetes sources to monitor high-privilege access grants and pod-identity abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
