mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-29 14:38:50 +00:00
30 lines
53 KiB
HTML
30 lines
53 KiB
HTML
<!doctype html>
|
||
<html lang="en" dir="ltr" class="docs-wrapper docs-doc-page docs-version-current plugin-docs plugin-id-default docs-doc-id-reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration" data-has-hydrated="false">
|
||
<head>
|
||
<meta charset="UTF-8">
|
||
<meta name="generator" content="Docusaurus v2.4.3">
|
||
<title data-rh="true">EKS Cluster Configuration Reference | Rancher</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="https://ranchermanager.docs.rancher.com/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration"><meta data-rh="true" name="docusaurus_locale" content="en"><meta data-rh="true" name="docsearch:language" content="en"><meta data-rh="true" name="docusaurus_version" content="current"><meta data-rh="true" name="docusaurus_tag" content="docs-default-current"><meta data-rh="true" name="docsearch:version" content="current"><meta data-rh="true" name="docsearch:docusaurus_tag" content="docs-default-current"><meta data-rh="true" property="og:title" content="EKS Cluster Configuration Reference | Rancher"><meta data-rh="true" name="description" content="Account Access"><meta data-rh="true" property="og:description" content="Account Access"><link data-rh="true" rel="icon" href="/img/favicon.png"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration" hreflang="en"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/zh/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration" hreflang="zh"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration" hreflang="x-default"><link data-rh="true" rel="preconnect" href="https://30NEY6C9UY-dsn.algolia.net" crossorigin="anonymous"><link data-rh="true" rel="canonical" href="https://ranchermanager.docs.rancher.com/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration"><link rel="preconnect" href="https://www.googletagmanager.com">
|
||
<script>window.dataLayer=window.dataLayer||[]</script>
|
||
<script>!function(e,t,a,n,g){e[n]=e[n]||[],e[n].push({"gtm.start":(new Date).getTime(),event:"gtm.js"});var m=t.getElementsByTagName(a)[0],r=t.createElement(a);r.async=!0,r.src="https://www.googletagmanager.com/gtm.js?id=GTM-57KS2MW",m.parentNode.insertBefore(r,m)}(window,document,"script","dataLayer")</script>
|
||
|
||
|
||
|
||
<link rel="search" type="application/opensearchdescription+xml" title="Rancher" href="/opensearch.xml">
|
||
|
||
|
||
|
||
<script src="https://cdn.cookielaw.org/scripttemplates/otSDKStub.js" charset="UTF-8" data-domain-script="0f98beb0-fc4c-417d-a42e-564e2cae42d2" async></script>
|
||
<script src="/scripts/optanonwrapper.js" async></script><link rel="stylesheet" href="/assets/css/styles.dea80607.css">
|
||
<link rel="preload" href="/assets/js/runtime~main.d98f8a34.js" as="script">
|
||
<link rel="preload" href="/assets/js/main.e9ebdfba.js" as="script">
|
||
</head>
|
||
<body class="navigation-with-keyboard">
|
||
<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-57KS2MW" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript>
|
||
|
||
|
||
<script>!function(){function t(t){document.documentElement.setAttribute("data-theme",t)}var e=function(){var t=null;try{t=new URLSearchParams(window.location.search).get("docusaurus-theme")}catch(t){}return t}()||function(){var t=null;try{t=localStorage.getItem("theme")}catch(t){}return t}();t(null!==e?e:"light")}()</script><div id="__docusaurus">
|
||
<div role="region" aria-label="Skip to main content"><a class="skipToContent_fXgn" href="#__docusaurus_skipToContent_fallback">Skip to main content</a></div><nav aria-label="Main" class="navbar navbar--fixed-top"><div class="navbar__inner"><div class="navbar__items"><button aria-label="Toggle navigation bar" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/"><div class="navbar__logo"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--light_HNdA"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--dark_i4oU"></div><b class="navbar__title text--truncate"></b></a><div class="navbar__item dropdown dropdown--hoverable"><a aria-current="page" class="navbar__link active" aria-haspopup="true" aria-expanded="false" role="button" href="/">Latest</a><ul class="dropdown__menu"><li><a aria-current="page" class="dropdown__link dropdown__link--active" href="/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration">Latest</a></li><li><a class="dropdown__link" href="/v2.9/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration">v2.9 (Preview)</a></li><li><a class="dropdown__link" href="/v2.8/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration">v2.8</a></li><li><a class="dropdown__link" href="/v2.7/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration">v2.7</a></li><li><a class="dropdown__link" href="/v2.6/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration">v2.6</a></li><li><a class="dropdown__link" href="/v2.5/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration">v2.5</a></li><li><a class="dropdown__link" href="/v2.0-v2.4">v2.0-v2.4</a></li><li><a class="dropdown__link" href="/versions">All versions</a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link"><svg viewBox="0 0 24 24" width="20" height="20" aria-hidden="true" class="iconLanguage_nlXk"><path fill="currentColor" d="M12.87 15.07l-2.54-2.51.03-.03c1.74-1.94 2.98-4.17 3.71-6.53H17V4h-7V2H8v2H1v1.99h11.17C11.5 7.92 10.44 9.75 9 11.35 8.07 10.32 7.3 9.19 6.69 8h-2c.73 1.63 1.73 3.17 2.98 4.56l-5.09 5.02L4 19l5-5 3.11 3.11.76-2.04zM18.5 10h-2L12 22h2l1.12-3h4.75L21 22h2l-4.5-12zm-2.62 7l1.62-4.33L19.12 17h-3.24z"></path></svg>English</a><ul class="dropdown__menu"><li><a href="/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration" target="_self" rel="noopener noreferrer" class="dropdown__link dropdown__link--active" lang="en">English</a></li><li><a href="/zh/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration" target="_self" rel="noopener noreferrer" class="dropdown__link" lang="zh">简体中文</a></li></ul></div><div class="searchBox_ZlJk"><button type="button" class="DocSearch DocSearch-Button" aria-label="Search"><span class="DocSearch-Button-Container"><svg width="20" height="20" class="DocSearch-Search-Icon" viewBox="0 0 20 20"><path d="M14.386 14.386l4.0877 4.0877-4.0877-4.0877c-2.9418 2.9419-7.7115 2.9419-10.6533 0-2.9419-2.9418-2.9419-7.7115 0-10.6533 2.9418-2.9419 7.7115-2.9419 10.6533 0 2.9419 2.9418 2.9419 7.7115 0 10.6533z" stroke="currentColor" fill="none" fill-rule="evenodd" stroke-linecap="round" stroke-linejoin="round"></path></svg><span class="DocSearch-Button-Placeholder">Search</span></span><span class="DocSearch-Button-Keys"></span></button></div></div><div class="navbar__items navbar__items--right"><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">Quick Links</a><ul class="dropdown__menu"><li><a href="https://github.com/rancher/rancher" target="_blank" rel="noopener noreferrer" class="dropdown__link">GitHub<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://github.com/rancher/rancher-docs" target="_blank" rel="noopener noreferrer" class="dropdown__link">Docs GitHub<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">More from SUSE</a><ul class="dropdown__menu"><li><a href="https://www.rancher.com" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__rancher">Rancher<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><hr style="margin: 0.3rem 0;"></li><li><a href="https://elemental.docs.rancher.com/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__elemental">Elemental<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://fleet.rancher.io/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__fleet">Fleet<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://harvesterhci.io" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__harvester">Harvester<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://rancherdesktop.io/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__rancher__desktop">Rancher Desktop<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><hr style="margin: 0.3rem 0;"></li><li><a href="https://opensource.suse.com" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__suse">More Projects...<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div id="__docusaurus_skipToContent_fallback" class="main-wrapper mainWrapper_z2l0 docsWrapper_BCFX"><button aria-label="Scroll back to top" class="clean-btn theme-back-to-top-button backToTopButton_sjWU" type="button"></button><div class="docPage__5DB"><aside class="theme-doc-sidebar-container docSidebarContainer_b6E3"><div class="sidebarViewport_Xe31"><div class="sidebar_njMd"><nav aria-label="Docs sidebar" class="menu thin-scrollbar menu_SIkG"><ul class="theme-doc-sidebar-menu menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/">What is Rancher?</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/getting-started/overview">Getting Started</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/how-to-guides/new-user-guides">How-to Guides</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret menu__link--active" aria-expanded="true" href="/reference-guides/best-practices">Reference Guides</a></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/reference-guides/best-practices">Best Practice Guides</a><button aria-label="Toggle the collapsible sidebar category 'Best Practice Guides'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/reference-guides/rancher-manager-architecture">Rancher Architecture</a><button aria-label="Toggle the collapsible sidebar category 'Rancher Architecture'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--active" aria-expanded="true" tabindex="0" href="/reference-guides/cluster-configuration">Cluster Configuration</a><button aria-label="Toggle the collapsible sidebar category 'Cluster Configuration'" type="button" class="clean-btn menu__caret"></button></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-3 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--active" aria-expanded="true" tabindex="0" href="/reference-guides/cluster-configuration/rancher-server-configuration">Rancher Server Configuration</a><button aria-label="Toggle the collapsible sidebar category 'Rancher Server Configuration'" type="button" class="clean-btn menu__caret"></button></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-4 menu__list-item"><a class="menu__link" tabindex="0" href="/reference-guides/cluster-configuration/rancher-server-configuration/rke1-cluster-configuration">RKE Cluster Configuration Reference</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-4 menu__list-item"><a class="menu__link" tabindex="0" href="/reference-guides/cluster-configuration/rancher-server-configuration/rke2-cluster-configuration">RKE2 Cluster Configuration Reference</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-4 menu__list-item"><a class="menu__link" tabindex="0" href="/reference-guides/cluster-configuration/rancher-server-configuration/k3s-cluster-configuration">K3s Cluster Configuration Reference</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-4 menu__list-item"><a class="menu__link menu__link--active" aria-current="page" tabindex="0" href="/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration">EKS Cluster Configuration Reference</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-4 menu__list-item"><a class="menu__link" tabindex="0" href="/reference-guides/cluster-configuration/rancher-server-configuration/aks-cluster-configuration">AKS Cluster Configuration Reference</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-4 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/reference-guides/cluster-configuration/rancher-server-configuration/gke-cluster-configuration">GKE Cluster Configuration Reference</a><button aria-label="Toggle the collapsible sidebar category 'GKE Cluster Configuration Reference'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-4 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/reference-guides/cluster-configuration/rancher-server-configuration/use-existing-nodes">Use Existing Nodes</a><button aria-label="Toggle the collapsible sidebar category 'Use Existing Nodes'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-4 menu__list-item"><a class="menu__link" tabindex="0" href="/reference-guides/cluster-configuration/rancher-server-configuration/sync-clusters">Syncing Hosted Clusters</a></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-3 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/reference-guides/cluster-configuration/downstream-cluster-configuration">Downstream Cluster Configuration</a><button aria-label="Toggle the collapsible sidebar category 'Downstream Cluster Configuration'" type="button" class="clean-btn menu__caret"></button></div></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/reference-guides/single-node-rancher-in-docker">Single-Node Rancher in Docker</a><button aria-label="Toggle the collapsible sidebar category 'Single-Node Rancher in Docker'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/reference-guides/backup-restore-configuration">Backup & Restore Configuration</a><button aria-label="Toggle the collapsible sidebar category 'Backup & Restore Configuration'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/reference-guides/kubernetes-concepts">Kubernetes Concepts</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/reference-guides/monitoring-v2-configuration">Monitoring Configuration Reference</a><button aria-label="Toggle the collapsible sidebar category 'Monitoring Configuration Reference'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/reference-guides/prometheus-federator">Prometheus Federator</a><button aria-label="Toggle the collapsible sidebar category 'Prometheus Federator'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/reference-guides/user-settings">User Settings</a><button aria-label="Toggle the collapsible sidebar category 'User Settings'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/reference-guides/cli-with-rancher">CLI with Rancher</a><button aria-label="Toggle the collapsible sidebar category 'CLI with Rancher'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/reference-guides/rancher-cluster-tools">Cluster Tools for Logging, Monitoring, and Visibility</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/reference-guides/rancher-project-tools">Project Tools for Logging, Monitoring, and Visibility</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/reference-guides/system-tools">System Tools</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/reference-guides/rke1-template-example-yaml">RKE1 Example YAML</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/reference-guides/rancher-webhook">Rancher Webhook</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/reference-guides/rancher-security">Rancher Security Guides</a><button aria-label="Toggle the collapsible sidebar category 'Rancher Security Guides'" type="button" class="clean-btn menu__caret"></button></div></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" href="/integrations-in-rancher">Integrations in Rancher</a><button aria-label="Toggle the collapsible sidebar category 'Integrations in Rancher'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/faq/general-faq">FAQ</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/troubleshooting/general-troubleshooting">Troubleshooting</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/api/quickstart">Rancher Kubernetes API</a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/contribute-to-rancher">Contributing to Rancher</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/glossary">Glossary</a></li></ul></nav></div></div></aside><main class="docMainContainer_gTbr"><div class="container padding-top--md padding-bottom--lg"><div class="row"><div class="col docItemCol_VOVn"><div class="docItemContainer_Djhp"><article><nav class="theme-doc-breadcrumbs breadcrumbsContainer_Z_bl" aria-label="Breadcrumbs"><ul class="breadcrumbs" itemscope="" itemtype="https://schema.org/BreadcrumbList"><li class="breadcrumbs__item"><a aria-label="Home page" class="breadcrumbs__link" href="/"><svg viewBox="0 0 24 24" class="breadcrumbHomeIcon_YNFT"><path d="M10 19v-5h4v5c0 .55.45 1 1 1h3c.55 0 1-.45 1-1v-7h1.7c.46 0 .68-.57.33-.87L12.67 3.6c-.38-.34-.96-.34-1.34 0l-8.36 7.53c-.34.3-.13.87.33.87H5v7c0 .55.45 1 1 1h3c.55 0 1-.45 1-1z" fill="currentColor"></path></svg></a></li><li class="breadcrumbs__item"><span class="breadcrumbs__link">Reference Guides</span><meta itemprop="position" content="1"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item"><a class="breadcrumbs__link" itemprop="item" href="/reference-guides/cluster-configuration"><span itemprop="name">Cluster Configuration</span></a><meta itemprop="position" content="2"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item"><a class="breadcrumbs__link" itemprop="item" href="/reference-guides/cluster-configuration/rancher-server-configuration"><span itemprop="name">Rancher Server Configuration</span></a><meta itemprop="position" content="3"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item breadcrumbs__item--active"><span class="breadcrumbs__link" itemprop="name">EKS Cluster Configuration Reference</span><meta itemprop="position" content="4"></li></ul></nav><span class="theme-doc-version-badge badge badge--secondary">Version: Latest</span><div class="tocCollapsible_ETCw theme-doc-toc-mobile tocMobile_ITEo"><button type="button" class="clean-btn tocCollapsibleButton_TO0P">On this page</button></div><div class="theme-doc-markdown markdown"><header><h1>EKS Cluster Configuration Reference</h1></header><h3 class="anchor anchorWithStickyNavbar_LWe7" id="account-access">Account Access<a href="#account-access" class="hash-link" aria-label="Direct link to Account Access" title="Direct link to Account Access"></a></h3><p>Complete each drop-down and field using the information obtained for your IAM policy.</p><table><thead><tr><th>Setting</th><th>Description</th></tr></thead><tbody><tr><td>Region</td><td>From the drop-down choose the geographical region in which to build your cluster.</td></tr><tr><td>Cloud Credentials</td><td>Select the cloud credentials that you created for your IAM policy. For more information on creating cloud credentials in Rancher, refer to <a href="/reference-guides/user-settings/manage-cloud-credentials">this page.</a></td></tr></tbody></table><h3 class="anchor anchorWithStickyNavbar_LWe7" id="service-role">Service Role<a href="#service-role" class="hash-link" aria-label="Direct link to Service Role" title="Direct link to Service Role"></a></h3><p>Choose a <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/using-service-linked-roles.html" target="_blank" rel="noopener noreferrer">service role</a>.</p><table><thead><tr><th>Service Role</th><th>Description</th></tr></thead><tbody><tr><td>Standard: Rancher generated service role</td><td>If you choose this role, Rancher automatically adds a service role for use with the cluster.</td></tr><tr><td>Custom: Choose from your existing service roles</td><td>If you choose this role, Rancher lets you choose from service roles that you're already created within AWS. For more information on creating a custom service role in AWS, see the <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/using-service-linked-roles.html#create-service-linked-role" target="_blank" rel="noopener noreferrer">Amazon documentation</a>.</td></tr></tbody></table><h3 class="anchor anchorWithStickyNavbar_LWe7" id="secrets-encryption">Secrets Encryption<a href="#secrets-encryption" class="hash-link" aria-label="Direct link to Secrets Encryption" title="Direct link to Secrets Encryption"></a></h3><p>Optional: To encrypt secrets, select or enter a key created in <a href="https://docs.aws.amazon.com/kms/latest/developerguide/overview.html" target="_blank" rel="noopener noreferrer">AWS Key Management Service (KMS)</a></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="api-server-endpoint-access">API Server Endpoint Access<a href="#api-server-endpoint-access" class="hash-link" aria-label="Direct link to API Server Endpoint Access" title="Direct link to API Server Endpoint Access"></a></h3><p>Configuring Public/Private API access is an advanced use case. For details, refer to the EKS cluster endpoint access control <a href="https://docs.aws.amazon.com/eks/latest/userguide/cluster-endpoint.html" target="_blank" rel="noopener noreferrer">documentation.</a></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="private-only-api-endpoints">Private-only API Endpoints<a href="#private-only-api-endpoints" class="hash-link" aria-label="Direct link to Private-only API Endpoints" title="Direct link to Private-only API Endpoints"></a></h3><p>If you enable private and disable public API endpoint access when creating a cluster, then there is an extra step you must take in order for Rancher to connect to the cluster successfully. In this case, a pop-up will be displayed with a command that you will run on the cluster to register it with Rancher. Once the cluster is provisioned, you can run the displayed command anywhere you can connect to the cluster's Kubernetes API.</p><p>There are two ways to avoid this extra manual step:</p><ul><li>You can create the cluster with both private and public API endpoint access on cluster creation. You can disable public access after the cluster is created and in an active state and Rancher will continue to communicate with the EKS cluster.</li><li>You can ensure that Rancher shares a subnet with the EKS cluster. Then security groups can be used to enable Rancher to communicate with the cluster's API endpoint. In this case, the command to register the cluster is not needed, and Rancher will be able to communicate with your cluster. For more information on configuring security groups, refer to the <a href="https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html" target="_blank" rel="noopener noreferrer">security groups documentation</a>.</li></ul><h3 class="anchor anchorWithStickyNavbar_LWe7" id="public-access-endpoints">Public Access Endpoints<a href="#public-access-endpoints" class="hash-link" aria-label="Direct link to Public Access Endpoints" title="Direct link to Public Access Endpoints"></a></h3><p>Optionally limit access to the public endpoint via explicit CIDR blocks.</p><p>If you limit access to specific CIDR blocks, then it is recommended that you also enable the private access to avoid losing network communication to the cluster.</p><p>One of the following is required to enable private access:</p><ul><li>Rancher's IP must be part of an allowed CIDR block</li><li>Private access should be enabled, and Rancher must share a subnet with the cluster and have network access to the cluster, which can be configured with a security group</li></ul><p>For more information about public and private access to the cluster endpoint, refer to the <a href="https://docs.aws.amazon.com/eks/latest/userguide/cluster-endpoint.html" target="_blank" rel="noopener noreferrer">Amazon EKS documentation.</a></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="subnet">Subnet<a href="#subnet" class="hash-link" aria-label="Direct link to Subnet" title="Direct link to Subnet"></a></h3><table><thead><tr><th>Option</th><th>Description</th></tr></thead><tbody><tr><td>Standard: Rancher generated VPC and Subnet</td><td>While provisioning your cluster, Rancher generates a new VPC with 3 public subnets.</td></tr><tr><td>Custom: Choose from your existing VPC and Subnets</td><td>While provisioning your cluster, Rancher configures your Control Plane and nodes to use a VPC and Subnet that you've already <a href="https://docs.aws.amazon.com/vpc/latest/userguide/what-is-amazon-vpc.html" target="_blank" rel="noopener noreferrer">created in AWS</a>.</td></tr></tbody></table><p> For more information, refer to the AWS documentation for <a href="https://docs.aws.amazon.com/eks/latest/userguide/network_reqs.html" target="_blank" rel="noopener noreferrer">Cluster VPC Considerations</a>. Follow one of the sets of instructions below based on your selection from the previous step.</p><ul><li><a href="https://docs.aws.amazon.com/vpc/latest/userguide/what-is-amazon-vpc.html" target="_blank" rel="noopener noreferrer">What Is Amazon VPC?</a></li><li><a href="https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Subnets.html" target="_blank" rel="noopener noreferrer">VPCs and Subnets</a></li></ul><h3 class="anchor anchorWithStickyNavbar_LWe7" id="security-group">Security Group<a href="#security-group" class="hash-link" aria-label="Direct link to Security Group" title="Direct link to Security Group"></a></h3><p>Amazon Documentation:</p><ul><li><a href="https://docs.aws.amazon.com/eks/latest/userguide/sec-group-reqs.html" target="_blank" rel="noopener noreferrer">Cluster Security Group Considerations</a></li><li><a href="https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html" target="_blank" rel="noopener noreferrer">Security Groups for Your VPC</a></li><li><a href="https://docs.aws.amazon.com/vpc/latest/userguide/getting-started-ipv4.html#getting-started-create-security-group" target="_blank" rel="noopener noreferrer">Create a Security Group</a></li></ul><h3 class="anchor anchorWithStickyNavbar_LWe7" id="logging">Logging<a href="#logging" class="hash-link" aria-label="Direct link to Logging" title="Direct link to Logging"></a></h3><p>Configure control plane logs to send to Amazon CloudWatch. You are charged the standard CloudWatch Logs data ingestion and storage costs for any logs sent to CloudWatch Logs from your clusters.</p><p>Each log type corresponds to a component of the Kubernetes control plane. To learn more about these components, see <a href="https://kubernetes.io/docs/concepts/overview/components/" target="_blank" rel="noopener noreferrer">Kubernetes Components</a> in the Kubernetes documentation.</p><p>For more information on EKS control plane logging, refer to the official <a href="https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html" target="_blank" rel="noopener noreferrer">documentation.</a></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="managed-node-groups">Managed Node Groups<a href="#managed-node-groups" class="hash-link" aria-label="Direct link to Managed Node Groups" title="Direct link to Managed Node Groups"></a></h3><p>Amazon EKS managed node groups automate the provisioning and lifecycle management of nodes (Amazon EC2 instances) for Amazon EKS Kubernetes clusters.</p><p>For more information about how node groups work and how they are configured, refer to the <a href="https://docs.aws.amazon.com/eks/latest/userguide/managed-node-groups.html" target="_blank" rel="noopener noreferrer">EKS documentation.</a></p><h4 class="anchor anchorWithStickyNavbar_LWe7" id="user-provided-launch-templates">User-provided Launch Templates<a href="#user-provided-launch-templates" class="hash-link" aria-label="Direct link to User-provided Launch Templates" title="Direct link to User-provided Launch Templates"></a></h4><p>You can provide your own launch template ID and version to configure the EC2 instances in a node group. If you provide the launch template, none of the template settings will be configurable from Rancher. You must set all of the required options listed below in your launch template.</p><p>Also, if you provide the launch template, you can only update the template version, not the template ID. To use a new template ID, create a new managed node group.</p><table><thead><tr><th>Option</th><th>Description</th><th>Required/Optional</th></tr></thead><tbody><tr><td>Instance Type</td><td>Choose the <a href="https://aws.amazon.com/ec2/instance-types/" target="_blank" rel="noopener noreferrer">hardware specs</a> for the instance you're provisioning.</td><td>Required</td></tr><tr><td>Image ID</td><td>Specify a custom AMI for the nodes. Custom AMIs used with EKS must be <a href="https://aws.amazon.com/premiumsupport/knowledge-center/eks-custom-linux-ami/" target="_blank" rel="noopener noreferrer">configured properly</a></td><td>Optional</td></tr><tr><td>Node Volume Size</td><td>The launch template must specify an EBS volume with the desired size</td><td>Required</td></tr><tr><td>SSH Key</td><td>A key to be added to the instances to provide SSH access to the nodes</td><td>Optional</td></tr><tr><td>User Data</td><td>Cloud init script in <a href="https://docs.aws.amazon.com/eks/latest/userguide/launch-templates.html#launch-template-user-data" target="_blank" rel="noopener noreferrer">MIME multi-part format</a></td><td>Optional</td></tr><tr><td>Instance Resource Tags</td><td>Tag each EC2 instance and its volumes in the node group</td><td>Optional</td></tr></tbody></table><div class="theme-admonition theme-admonition-caution alert alert--warning admonition_LlT9"><div class="admonitionHeading_tbUL"><span class="admonitionIcon_kALy"><svg viewBox="0 0 16 16"><path fill-rule="evenodd" d="M8.893 1.5c-.183-.31-.52-.5-.887-.5s-.703.19-.886.5L.138 13.499a.98.98 0 0 0 0 1.001c.193.31.53.501.886.501h13.964c.367 0 .704-.19.877-.5a1.03 1.03 0 0 0 .01-1.002L8.893 1.5zm.133 11.497H6.987v-2.003h2.039v2.003zm0-3.004H6.987V5.987h2.039v4.006z"></path></svg></span>caution</div><div class="admonitionContent_S0QG"><p>You can't directly update a node group to a newer Kubernetes version if the node group was created from a custom launch template. You must create a new launch template with the proper Kubernetes version, and associate the node group with the new template.</p></div></div><h4 class="anchor anchorWithStickyNavbar_LWe7" id="rancher-managed-launch-templates">Rancher-managed Launch Templates<a href="#rancher-managed-launch-templates" class="hash-link" aria-label="Direct link to Rancher-managed Launch Templates" title="Direct link to Rancher-managed Launch Templates"></a></h4><p>If you do not specify a launch template, then you will be able to configure the above options in the Rancher UI and all of them can be updated after creation. In order to take advantage of all of these options, Rancher will create and manage a launch template for you. Each cluster in Rancher will have one Rancher-managed launch template and each managed node group that does not have a specified launch template will have one version of the managed launch template. The name of this launch template will have the prefix "rancher-managed-lt-" followed by the display name of the cluster. In addition, the Rancher-managed launch template will be tagged with the key "rancher-managed-template" and value "do-not-modify-or-delete" to help identify it as Rancher-managed. It is important that this launch template and its versions not be modified, deleted, or used with any other clusters or managed node groups. Doing so could result in your node groups being "degraded" and needing to be destroyed and recreated.</p><h4 class="anchor anchorWithStickyNavbar_LWe7" id="custom-amis">Custom AMIs<a href="#custom-amis" class="hash-link" aria-label="Direct link to Custom AMIs" title="Direct link to Custom AMIs"></a></h4><p>If you specify a custom AMI, whether in a launch template or in Rancher, then the image must be <a href="https://aws.amazon.com/premiumsupport/knowledge-center/eks-custom-linux-ami/" target="_blank" rel="noopener noreferrer">configured properly</a> and you must provide user data to <a href="https://docs.aws.amazon.com/eks/latest/userguide/launch-templates.html#launch-template-custom-ami" target="_blank" rel="noopener noreferrer">bootstrap the node</a>. This is considered an advanced use case and understanding the requirements is imperative.</p><p>If you specify a launch template that does not contain a custom AMI, then Amazon will use the <a href="https://docs.aws.amazon.com/eks/latest/userguide/eks-optimized-ami.html" target="_blank" rel="noopener noreferrer">EKS-optimized AMI</a> for the Kubernetes version and selected region. You can also select a <a href="https://docs.aws.amazon.com/eks/latest/userguide/eks-optimized-ami.html#gpu-ami" target="_blank" rel="noopener noreferrer">GPU enabled instance</a> for workloads that would benefit from it.</p><div class="theme-admonition theme-admonition-note alert alert--secondary admonition_LlT9"><div class="admonitionHeading_tbUL"><span class="admonitionIcon_kALy"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>note</div><div class="admonitionContent_S0QG"><p>The GPU enabled instance setting in Rancher is ignored if a custom AMI is provided, either in the dropdown or in a launch template.</p></div></div><h4 class="anchor anchorWithStickyNavbar_LWe7" id="spot-instances">Spot instances<a href="#spot-instances" class="hash-link" aria-label="Direct link to Spot instances" title="Direct link to Spot instances"></a></h4><p>Spot instances are now <a href="https://docs.aws.amazon.com/eks/latest/userguide/managed-node-groups.html#managed-node-group-capacity-types-spot" target="_blank" rel="noopener noreferrer">supported by EKS</a>. If a launch template is specified, Amazon recommends that the template not provide an instance type. Instead, Amazon recommends providing multiple instance types. If the "Request Spot Instances" checkbox is enabled for a node group, then you will have the opportunity to provide multiple instance types.</p><div class="theme-admonition theme-admonition-note alert alert--secondary admonition_LlT9"><div class="admonitionHeading_tbUL"><span class="admonitionIcon_kALy"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>note</div><div class="admonitionContent_S0QG"><p>Any selection you made in the instance type dropdown will be ignored in this situation and you must specify at least one instance type to the "Spot Instance Types" section. Furthermore, a launch template used with EKS cannot request spot instances. Requesting spot instances must be part of the EKS configuration.</p></div></div><h4 class="anchor anchorWithStickyNavbar_LWe7" id="node-group-settings">Node Group Settings<a href="#node-group-settings" class="hash-link" aria-label="Direct link to Node Group Settings" title="Direct link to Node Group Settings"></a></h4><p>The following settings are also configurable. All of these except for the "Node Group Name" are editable after the node group is created.</p><table><thead><tr><th>Option</th><th>Description</th></tr></thead><tbody><tr><td>Node Group Name</td><td>The name of the node group.</td></tr><tr><td>Desired ASG Size</td><td>The desired number of instances.</td></tr><tr><td>Maximum ASG Size</td><td>The maximum number of instances. This setting won't take effect until the <a href="https://docs.aws.amazon.com/eks/latest/userguide/cluster-autoscaler.html" target="_blank" rel="noopener noreferrer">Cluster Autoscaler</a> is installed.</td></tr><tr><td>Minimum ASG Size</td><td>The minimum number of instances. This setting won't take effect until the <a href="https://docs.aws.amazon.com/eks/latest/userguide/cluster-autoscaler.html" target="_blank" rel="noopener noreferrer">Cluster Autoscaler</a> is installed.</td></tr><tr><td>Labels</td><td>Kubernetes labels applied to the nodes in the managed node group.</td></tr><tr><td>Tags</td><td>These are tags for the managed node group and do not propagate to any of the associated resources.</td></tr></tbody></table><h3 class="anchor anchorWithStickyNavbar_LWe7" id="self-managed-amazon-linux-nodes">Self-managed Amazon Linux Nodes<a href="#self-managed-amazon-linux-nodes" class="hash-link" aria-label="Direct link to Self-managed Amazon Linux Nodes" title="Direct link to Self-managed Amazon Linux Nodes"></a></h3><p>You can register an EKS cluster containing self-managed Amazon Linux nodes. You must configure this type of cluster according to the instructions in the official AWS documentation for <a href="https://docs.aws.amazon.com/eks/latest/userguide/launch-workers.html" target="_blank" rel="noopener noreferrer">launching self-managed Amazon Linux nodes</a>. EKS clusters containing self-managed Amazon Linux nodes are usually operated by the <a href="https://karpenter.sh/docs/" target="_blank" rel="noopener noreferrer">Karpenter</a> project. After you provision an EKS cluster containing self-managed Amazon Linux nodes, <a href="/how-to-guides/new-user-guides/kubernetes-clusters-in-rancher-setup/register-existing-clusters">register the cluster</a> so it can be managed by Rancher. However, the nodes won't be visible in the Rancher UI.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="iam-roles-for-service-accounts">IAM Roles for Service Accounts<a href="#iam-roles-for-service-accounts" class="hash-link" aria-label="Direct link to IAM Roles for Service Accounts" title="Direct link to IAM Roles for Service Accounts"></a></h3><p>An Applications Deployment running on an EKS cluster can make requests to AWS services via IAM permissions. These applications must sign their requests with AWS credentials. IAM roles for service accounts manage these credentials using an AWS OIDC endpoint. Rather than distributing AWS credentials to containers or relying on an EC2 instance's role, you can link an <a href="https://docs.aws.amazon.com/eks/latest/userguide/iam-roles-for-service-accounts.html" target="_blank" rel="noopener noreferrer">IAM role to a Kubernetes service account</a> and configure your Pods to use this account.</p><div class="theme-admonition theme-admonition-note alert alert--secondary admonition_LlT9"><div class="admonitionHeading_tbUL"><span class="admonitionIcon_kALy"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>note</div><div class="admonitionContent_S0QG"><p>Linking to an IAM role is not supported for Rancher pods in an EKS cluster.</p></div></div><p>To enable IAM roles for service accounts:</p><ol><li><a href="https://docs.aws.amazon.com/eks/latest/userguide/enable-iam-roles-for-service-accounts.html" target="_blank" rel="noopener noreferrer">Create an IAM OIDC provider for your cluster</a></li><li><a href="https://docs.aws.amazon.com/eks/latest/userguide/associate-service-account-role.html" target="_blank" rel="noopener noreferrer">Configure a Kubernetes service account to assume an IAM role</a></li><li><a href="https://docs.aws.amazon.com/eks/latest/userguide/pod-configuration.html" target="_blank" rel="noopener noreferrer">Configure Pods to use a Kubernetes service account</a></li><li><a href="https://docs.aws.amazon.com/eks/latest/userguide/iam-roles-for-service-accounts-minimum-sdk.html" target="_blank" rel="noopener noreferrer">Use a supported AWS SDK</a></li></ol><h3 class="anchor anchorWithStickyNavbar_LWe7" id="configuring-the-refresh-interval">Configuring the Refresh Interval<a href="#configuring-the-refresh-interval" class="hash-link" aria-label="Direct link to Configuring the Refresh Interval" title="Direct link to Configuring the Refresh Interval"></a></h3><p>The <code>eks-refresh-cron</code> setting is deprecated. It has been migrated to the <code>eks-refresh</code> setting, which is an integer representing seconds.</p><p>The default value is 300 seconds.</p><p>The syncing interval can be changed by running <code>kubectl edit setting eks-refresh</code>.</p><p>If the <code>eks-refresh-cron</code> setting was previously set, the migration will happen automatically.</p><p>The shorter the refresh window, the less likely any race conditions will occur, but it does increase the likelihood of encountering request limits that may be in place for AWS APIs.</p></div><footer class="theme-doc-footer docusaurus-mt-lg"><div class="theme-doc-footer-edit-meta-row row"><div class="col"><a href="https://github.com/rancher/rancher-docs/edit/main/docs/reference-guides/cluster-configuration/rancher-server-configuration/eks-cluster-configuration.md" target="_blank" rel="noreferrer noopener" class="theme-edit-this-page"><svg fill="currentColor" height="20" width="20" viewBox="0 0 40 40" class="iconEdit_Z9Sw" aria-hidden="true"><g><path d="m34.5 11.7l-3 3.1-6.3-6.3 3.1-3q0.5-0.5 1.2-0.5t1.1 0.5l3.9 3.9q0.5 0.4 0.5 1.1t-0.5 1.2z m-29.5 17.1l18.4-18.5 6.3 6.3-18.4 18.4h-6.3v-6.2z"></path></g></svg>Edit this page</a></div><div class="col lastUpdated_vwxv"><span class="theme-last-updated">Last updated<!-- --> on <b><time datetime="2024-03-07T16:56:04.000Z">Mar 7, 2024</time></b></span></div></div></footer></article><nav class="pagination-nav docusaurus-mt-lg" aria-label="Docs pages"><a class="pagination-nav__link pagination-nav__link--prev" href="/reference-guides/cluster-configuration/rancher-server-configuration/k3s-cluster-configuration"><div class="pagination-nav__sublabel">Previous</div><div class="pagination-nav__label">K3s Cluster Configuration Reference</div></a><a class="pagination-nav__link pagination-nav__link--next" href="/reference-guides/cluster-configuration/rancher-server-configuration/aks-cluster-configuration"><div class="pagination-nav__sublabel">Next</div><div class="pagination-nav__label">AKS Cluster Configuration Reference</div></a></nav></div></div><div class="col col--3"><div class="tableOfContents_bqdL thin-scrollbar theme-doc-toc-desktop"><ul class="table-of-contents table-of-contents__left-border"><li><a href="#account-access" class="table-of-contents__link toc-highlight">Account Access</a></li><li><a href="#service-role" class="table-of-contents__link toc-highlight">Service Role</a></li><li><a href="#secrets-encryption" class="table-of-contents__link toc-highlight">Secrets Encryption</a></li><li><a href="#api-server-endpoint-access" class="table-of-contents__link toc-highlight">API Server Endpoint Access</a></li><li><a href="#private-only-api-endpoints" class="table-of-contents__link toc-highlight">Private-only API Endpoints</a></li><li><a href="#public-access-endpoints" class="table-of-contents__link toc-highlight">Public Access Endpoints</a></li><li><a href="#subnet" class="table-of-contents__link toc-highlight">Subnet</a></li><li><a href="#security-group" class="table-of-contents__link toc-highlight">Security Group</a></li><li><a href="#logging" class="table-of-contents__link toc-highlight">Logging</a></li><li><a href="#managed-node-groups" class="table-of-contents__link toc-highlight">Managed Node Groups</a></li><li><a href="#self-managed-amazon-linux-nodes" class="table-of-contents__link toc-highlight">Self-managed Amazon Linux Nodes</a></li><li><a href="#iam-roles-for-service-accounts" class="table-of-contents__link toc-highlight">IAM Roles for Service Accounts</a></li><li><a href="#configuring-the-refresh-interval" class="table-of-contents__link toc-highlight">Configuring the Refresh Interval</a></li></ul></div></div></div></div></main></div></div><footer class="footer footer--dark"><div class="container container-fluid"><div class="footer__bottom text--center"><div class="footer__copyright">Copyright © 2024 SUSE Rancher. All Rights Reserved.</div></div></div></footer></div>
|
||
<script src="/assets/js/runtime~main.d98f8a34.js"></script>
|
||
<script src="/assets/js/main.e9ebdfba.js"></script>
|
||
</body>
|
||
</html> |