terraform-aws-eks
terraform-aws-eks copied to clipboard
Stop pods from using the node instance profile
This is relevant https://docs.aws.amazon.com/eks/latest/userguide/restrict-ec2-credential-access.html
I suspect if we did this it would stop the node termination handler accessing the metadata service... could we find a workaround?
https://docs.aws.amazon.com/eks/latest/userguide/best-practices-security.html#restrict-ec2-credential-access
Before we can make this change we have to check that anything not running in the host network that needs IAM permissions, and is currently relying on them.
I think the CNI plugin might ... but we would need to check!