Apply whitelist on EKS Public endpoint and enable private endpoints
We will allow you to set a CIDR whitelist on the public endpoints of your managed EKS cluster. This is mostly required for compliance reasons.
We will also enable the private endpoint of your EKS cluster.
Log in to comment and vote
Comments1
Alessandro Carrano
Oct 11, 2024
The feature has been delivered! Note: it is available only for AWS clusters
We strongly recommend you to test it on your non-production cluster before moving to the production one.
how to activate it:
ensure to have a [Dockerhub registry] created and configured with your own credentials. As explained above, this is a requirement we have set to avoid rate limit issues when pulling images from the Dockerhub registry (more info here).
set the cluster advanced settings
qovery.static_ip_modeto truere-deploy your cluster
This will apply a whitelist on the cluster public endpoints and activate the private endpoint.
if you need access to the Kube API from other locations (like connecting via k9s from your own laptop), you will have to add those additional IP/CIDR in the advanced settings k8s.api.allowed_public_access_cidrs
Let me know if you need more information