Amazon EKS
Connect Amazon EKS to Iru Compliance Automation to collect cluster inventory, node-group configuration, and add-on metadata as evidence.
Cluster access and API activity are two different questions in Kubernetes, and Iru connects to AWS EKS to answer both — reading RBAC configuration, IRSA role mappings, and API server audit logs directly.
Key Capabilities
- Verify cluster access is governed by RBAC
- Confirm workload identity is scoped through IRSA
- Check that the Kubernetes API server isn't broadly reachable
- Track API activity as it's audited
Evidence Collected
- Kubernetes API server audit logs streamed to CloudWatch
- RBAC and cluster access configuration
- IRSA role mappings
- Network segmentation and API endpoint reachability
- Node group and Fargate maintenance configuration