Dilshan discusses a real incident where migrating EKS nodes to AL2023 caused the cluster autoscaler to lose AWS permissions silently.
You will learn:
- Why AL2023 blocks pod access to instance metadata by default, breaking components that relied on node IAM roles
- How to implement IRSA correctly by configuring IAM roles, Kubernetes service accounts, and OIDC trust relationships, and why both AWS IAM and Kubernetes RBAC must be configured independently
- How to audit which pods currently rely on node roles and clean up legacy IAM permissions to reduce attack surface after migration
Watch (or listen to) it here: https://ku.bz/T_YPfTfDb
🌟 This episode is brought to you by LearnKube — join their 4-day hands-on Advanced Kubernetes course starting January 29th and finally get comfortable with production clusters. https://learnkube.com/training
With @Birthmarkb "Keep Working Harder" Farrell
Post #1623
308
Forwarded from KubeFM