All skills
aws avatar

/aws-containers

@df5d2e8

Builds and deploys containerized workloads on Elastic Kubernetes Service (EKS), Elastic Container Service (ECS), Fargate, and ECR (Elastic Container Registry). Covers general EKS knowledge, Karpenter, AWS Load Balancer Controller and leveraging various open source Kubernetes projects with EKS. Covers general ECS knowledge, task definitions, Fargate services, ECS Exec, ECS Express Mode and ECS Managed Instances. Covers general Elastic Beanstalk knowledge, Elastic Beanstalk configuration and platforms supported by Elastic Beanstalk. Covers general ECR knowledge, ECR repository setup and lifecycle policies. Includes recommending, enabling, and reading Amazon ECS Action Logs to troubleshoot control-plane failures (deployment rollback/circuit-breaker, task placement, scaling, task replacement). Applies when deploying, debugging, or optimizing containers on AWS. Should be used instead of relying on internal knowledge for these services.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-containers

This session only. Nothing lands on disk.

referenceseks-auto-mode.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

EKS Auto Mode

EKS Auto Mode extends AWS management of Kubernetes clusters beyond the cluster itself, to allow AWS to also set up and manage the infrastructure that enables the smooth operation of your workloads. You can delegate key infrastructure decisions and leverage the expertise of AWS for day-to-day operations. Cluster infrastructure managed by AWS includes many Kubernetes capabilities as core components, as opposed to add-ons, such as compute autoscaling, pod and service networking, application load balancing, cluster DNS, block storage, and GPU support.

In general it is critical to avoid making assumptions about EKS Auto Mode clusters, their capabilities and how to configure them relative to traditional EKS clusters. The EKS Auto Mode documentation should be referred to as much as needed to make informed decisions.

Compute

EKS Auto Mode relies on Karpenter autoscaling to provision and manage cluster compute, and nodes are designed to be treated like appliances. EKS Auto Mode does the following:

  • Chooses an appropriate AMI that’s configured with many services needed to run your workloads without intervention.
  • Locks down access to files on the AMI using SELinux enforcing mode and a read-only root file system.
  • Prevents direct access to the nodes by disallowing SSH or SSM access.
  • Includes GPU support, with separate kernel drivers and plugins for NVIDIA and Neuron GPUs, enabling high-performance workloads.
  • Automatically handles EC2 Spot Instance interruption notices and EC2 Instance health events

Node Classes

Amazon EKS Node Classes are templates that offer granular control over the configuration of your EKS Auto Mode managed nodes. A Node Class defines infrastructure-level settings that apply to groups of nodes in your EKS cluster, including network configuration, storage settings, and resource tagging.

EKS Auto Mode uses a node class CRD that is different from standard Karpenter. You must refer to the relevant EKS Auto Mode documentation when answering questions or authoring configurations related to Auto Mode node classes.

Node Pools

Amazon EKS node pools offer a flexible way to manage compute resources in your Kubernetes cluster. This topic demonstrates how to create and configure node pools by using Karpenter, a node provisioning tool that helps optimize cluster scaling and resource utilization. With Karpenter’s NodePool resource, you can define specific requirements for your compute resources, including instance types, availability zones, architectures, and capacity types.

EKS Auto Mode uses different labels than Karpenter. Labels related to EC2 managed instances start with eks.amazonaws.com.

See the relevant documentation for more information on EKS Auto Mode node pools.

Networking

EKS Auto Mode has some networking capabilities that differ from standard EKS clusters.

Ingress

EKS Auto Mode creates and configures Application Load Balancers (ALBs). For example, EKS Auto Mode creates a load balancer when you create an Ingress Kubernetes object and configures it to route traffic to your cluster workload.

This works much the same way as the AWS Load Balancer Controller but is a different implementation. Key differences include:

  • Certain Ingress annotations are not supported, see the documentation for details before recommending certain annotations.
  • You cannot use Annotations on an IngressClass to configure load balancers with EKS Auto Mode. IngressClass configuration should be done through IngressClassParams.
  • TargetGroupBinding and IngressClassParams CRDs have different signatures, see the documentation for details.

See the documentation for more information.

Network policies

EKS Auto Mode supports the following through network policies:

  • L3/L4 isolation
  • DNS-based environment
  • Admin (or cluster-scoped) rules

See the documentation for more information.

Source: SKILL.md on GitHub

No alertstoday3 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    This skill provides technical guidance for AWS container services and appears to follow security best practices, such as recommending the use of Secrets Manager and least-privilege IAM roles. All external resources originate from official or well-known sources, and no security issues were detected.

  • Sockettoday

    No alerts

  • Snyktoday

    Risk: LOW · No issues

Signed by skilld at df5d2e8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 weeks ago
What it can do
Reads files
metadata
{
  "version": "2"
}
All 1 allowed tools
Read

README badge

README badge for aws/agent-toolkit-for-aws/aws-containers