All skills
aws avatar

/aws-containers

@df5d2e8

Builds and deploys containerized workloads on Elastic Kubernetes Service (EKS), Elastic Container Service (ECS), Fargate, and ECR (Elastic Container Registry). Covers general EKS knowledge, Karpenter, AWS Load Balancer Controller and leveraging various open source Kubernetes projects with EKS. Covers general ECS knowledge, task definitions, Fargate services, ECS Exec, ECS Express Mode and ECS Managed Instances. Covers general Elastic Beanstalk knowledge, Elastic Beanstalk configuration and platforms supported by Elastic Beanstalk. Covers general ECR knowledge, ECR repository setup and lifecycle policies. Includes recommending, enabling, and reading Amazon ECS Action Logs to troubleshoot control-plane failures (deployment rollback/circuit-breaker, task placement, scaling, task replacement). Applies when deploying, debugging, or optimizing containers on AWS. Should be used instead of relying on internal knowledge for these services.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-containers

This session only. Nothing lands on disk.

referenceseks-networking.md

≈755 tokens on demand. Your agent reads this file only when SKILL.md points to it.

EKS Networking

Your Amazon EKS cluster is created in a VPC. Pod networking is provided by the Amazon VPC Container Network Interface (CNI) plugin for nodes that run on AWS infrastructure.

Amazon VPC CNI

The Amazon VPC CNI plugin for Kubernetes add-on is deployed on each Amazon EC2 node in your Amazon EKS cluster. The add-on creates elastic network interfaces and attaches them to your Amazon EC2 nodes. The add-on also assigns a private IPv4 or IPv6 address from your VPC to each Pod.

Network policies

By default, there are no restrictions in Kubernetes for IP addresses, ports, or connections between any Pods in your cluster or between your Pods and resources in any other network. You can use Kubernetes network policy to restrict network traffic to and from your Pods.

EKS supports different types of network policies.

Layer 3 and 4 isolation

Standard Kubernetes network policies operate at layers 3 and 4 of the OSI network model and allow you to control traffic flow at the IP address or port level within your Amazon EKS cluster.

Use cases:

  • Segment network traffic between workloads to ensure that only related applications can talk to each other.
  • Isolate tenants at the namespace level using policies to enforce network separation.

This is available through the Amazon VPC CNI and EKS Auto Mode (see eks-auto-mode.md).

See the documentation.

DNS-based enforcement

Domain Name System (DNS) based policies allow you to strengthen your security posture by adopting a more stable and predictable approach for preventing unauthorized access from pods to cluster-external resources or endpoints. This mechanism eliminates the need to manually track and allow list specific IP addresses.

Use cases:

  • Standardize on a DNS-based approach for filtering access from a Kubernetes environment to cluster-external endpoints.
  • Secure access to AWS services in a multi-tenant environment.
  • Manage network access from pods to on-prem workloads in your Hybrid cloud environments.

DNS-based enforcement is only available on EKS Auto Mode (see eks-auto-mode.md).

Admin (or cluster-scoped) rules

In some cases, like multi-tenant scenarios, customers may have the requirement to enforce a network security standard that applies to the whole cluster. Instead of repetitively defining and maintaining a distinct policy for each namespace, you can use a single policy to centrally manage network access controls for different workloads in the cluster, irrespective of their namespace.

Use cases:

  • Centrally manage network access controls for all (or a subset of) workloads in your EKS cluster.
  • Define a default network security posture across the cluster.
  • Extend organizational security standards to the scope of the cluster in a more operationally efficient way.

Admin policies are only available on EKS Auto Mode (see eks-auto-mode.md).

Source: SKILL.md on GitHub

No alertstoday3 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    This skill provides technical guidance for AWS container services and appears to follow security best practices, such as recommending the use of Secrets Manager and least-privilege IAM roles. All external resources originate from official or well-known sources, and no security issues were detected.

  • Sockettoday

    No alerts

  • Snyktoday

    Risk: LOW · No issues

Signed by skilld at df5d2e8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 weeks ago
What it can do
Reads files
metadata
{
  "version": "2"
}
All 1 allowed tools
Read

README badge

README badge for aws/agent-toolkit-for-aws/aws-containers