Amazon EKS connector
The Amazon EKS connector gives an agent the AWS control-plane side of managed Kubernetes: it discovers clusters, reads cluster and node group state, scales node groups to add or drain capacity, and audits who can reach a cluster through EKS access entries and access policies. Through the connector execute API, it also manages access entries and mints the short-lived Kubernetes bearer token that EKS requires, without an interactive aws eks get-token.
This connector is currently available in Agent Builder only. Workflow support is planned for a future release.
It does not touch workloads. Pods, deployments, logs, and kubectl-style apply, scale, and rollout belong to the Kubernetes connector, which accepts the same AWS access key through its Amazon EKS authentication type. The getCluster action returns the endpoint and CA certificate that connector needs.
The connector calls the Amazon EKS API in the configured Region, signing every request with AWS Signature Version 4 using the access key you provide. getToken additionally presigns an AWS STS GetCallerIdentity request with the same key, which is how EKS bearer tokens work.
Node group and cluster configuration changes are asynchronous updates. Poll describeUpdate with the returned update ID, cluster name, and Region until done is true, then check succeeded and errors. Access entry and policy changes apply immediately.
Access entry management (createAccessEntry, updateAccessEntry, deleteAccessEntry, associateAccessPolicy, disassociateAccessPolicy), updateClusterAccessConfig, and getToken are not available to agents, because they grant cluster access, can lock clients out of the cluster, or return a live credential. You can call them only through the connector execute API.
You can create connectors in Stack Management > Connectors.
Amazon EKS connectors have the following configuration properties:
- AWS Region
- The AWS Region the clusters live in, for example
us-east-1orus-gov-west-1. Every action can override it with aregionparameter. China and ISO Regions are not supported.
AWS credentials
- Access Key ID
- The AWS IAM access key ID used to sign every request with Signature Version 4 (SigV4) and to presign cluster tokens.
- Secret Access Key
- The AWS IAM secret access key paired with the access key ID above.
You can test connectors when you create or edit the connector in Kibana. The test calls the EKS ListClusters API in the configured Region to verify connectivity and that the credentials can authenticate.
Every action accepts an optional region that overrides the connector setting.
listClusters- Lists the cluster names in a Region. Parameters:
maxResults,nextToken,includeConnectedClusters. getCluster- Describes a cluster: status, Kubernetes and platform version, API server endpoint, CA certificate, authentication mode, enabled control-plane log types, VPC and endpoint access settings, health issues, and tags. Also returns
kubernetesConnectorwith the API URL and PEM CA certificate for wiring the Kubernetes connector to the cluster. Clusters registered through the EKS Connector have no endpoint, sokubernetesConnectoris absent for them. Whenvpc.endpointPublicAccessisfalse, the endpoint is reachable only from inside the cluster's VPC. Parameters:clusterName. getToken- Mints a short-lived Kubernetes bearer token for the cluster and, by default, returns the endpoint and CA certificate with it, ready for a call to the Kubernetes API. Tokens are reported as valid for 14 minutes, one minute less than EKS accepts them. The connector's IAM identity must already have an access entry on the cluster. Fails for a cluster without an API server endpoint. Parameters:
clusterName,includeClusterDetails. Execute API only.
listNodegroups- Lists the managed node group names of a cluster. Parameters:
clusterName,maxResults,nextToken. describeNodegroup- Describes a managed node group: status, scaling configuration (
minSize,maxSize,desiredSize), capacity type, instance types, AMI type, version, labels, taints, update strategy, node repair, Auto Scaling groups, and health issues. Parameters:clusterName,nodegroupName. updateNodegroupConfig- Scales a node group or changes its labels, taints, rolling-update settings, or node auto repair. Parameters:
clusterName,nodegroupName, and at least one ofminSize,maxSize,desiredSize,labelsToAdd,labelsToRemove,taintsToAdd,taintsToRemove,maxUnavailable,maxUnavailablePercentage,updateStrategy,nodeRepairEnabled. Settings you omit keep their current values. Returns an update, with the cluster name and Region to poll it with.
describeUpdate- Gets the status of an asynchronous update: status, a
doneflag,succeeded, the changed parameters, and errors. Parameters:clusterName,updateId, andnodegroupNamefor node group updates. listUpdates- Lists update IDs for a cluster or, with
nodegroupName, for one node group. Parameters:clusterName,nodegroupName,maxResults,nextToken.
updateClusterConfig- Changes one category of control-plane settings per call: control-plane logging (
enableLogTypes,disableLogTypes), the upgrade policy (supportType), ordeletionProtection. EKS rejects an update that mixes categories, so the connector does too. Returns an update, with the cluster name and Region to poll it with. updateClusterAccessConfig- Changes how clients reach the cluster, one category per call: the authentication mode (
authenticationMode, forward only:CONFIG_MAPtoAPI_AND_CONFIG_MAPtoAPI; switching toAPIdisables theaws-authConfigMap and can't be undone), or API endpoint access (endpointPublicAccess,endpointPrivateAccess,publicAccessCidrs). Endpoint settings you omit keep their current values. Returns an update, with the cluster name and Region to poll it with. Execute API only. listTagsForResource- Reads the AWS tags on a cluster or node group. Parameters:
resourceArn.
listAccessPolicies- Lists the EKS-managed access policies and their ARNs, such as
AmazonEKSClusterAdminPolicy,AmazonEKSAdminPolicy,AmazonEKSEditPolicy, andAmazonEKSViewPolicy. listAccessEntries- Lists the IAM principal ARNs that have an access entry on a cluster. Parameters:
clusterName,associatedPolicyArn,maxResults,nextToken. describeAccessEntry- Describes one principal's access entry: type, Kubernetes username and groups, and tags. Parameters:
clusterName,principalArn. listAssociatedAccessPolicies- Lists the access policies bound to a principal's access entry with their scope. Parameters:
clusterName,principalArn. createAccessEntry- Creates an access entry so an IAM user or role can authenticate to the cluster. Parameters:
clusterName,principalArn, and optionalkubernetesGroups,username,type,tags. Execute API only. updateAccessEntry- Replaces the Kubernetes groups or username of an access entry. The one you omit keeps its current value. Parameters:
clusterName,principalArn, andkubernetesGroupsorusername. Execute API only. deleteAccessEntry- Deletes an access entry, revoking the principal's cluster access. Parameters:
clusterName,principalArn. Execute API only. associateAccessPolicy- Binds an access policy to an access entry, cluster-wide or scoped to namespaces. Parameters:
clusterName,principalArn,policyArn,accessScopeType,namespaces. Execute API only. disassociateAccessPolicy- Removes an access policy from an access entry. Parameters:
clusterName,principalArn,policyArn. Execute API only.
- Node group sizes are totals across the group's subnets, not per zone.
desiredSizemust stay withinminSizeandmaxSize, so widenmaxSizein the same call when scaling past the current maximum. If the Cluster Autoscaler or Karpenter manages the group, change the bounds instead ofdesiredSize. - Updates are slow. Node group scaling takes 1 to 5 minutes; control-plane changes such as logging or endpoint access take 5 to 25 minutes. Do not wait for an update in a single call: keep the update ID and poll
describeUpdatelater, with a wait between polls, so the calling agent turn does not time out. EKS runs one update per node group and one cluster-level update at a time. - To let the connector's IAM identity (or any other principal) reach the Kubernetes API, create an access entry, then bind an access policy to it, with
createAccessEntryandassociateAccessPolicythrough the execute API or in the EKS console. Access entries require the cluster authentication modeAPIorAPI_AND_CONFIG_MAP. - To manage workloads from Kibana, create a Kubernetes connector with the Amazon EKS authentication type, the same access key, the Region and cluster name, and the
kubernetesConnector.apiUrlandcaCertificatePemreturned bygetCluster. That connector mints its own token on every call, sogetTokenis only needed when another system consumes the token. updateAccessEntryreplaces the Kubernetes group list, andupdateClusterAccessConfigreplaces the public CIDR allowlist when you passpublicAccessCidrs. Read the current values first and include everything you want to keep.
Use the Action configuration settings to customize connector networking, such as proxies, certificates, or TLS settings. You can set configurations that apply to all your connectors or use xpack.actions.customHostSettings to set per-host configurations.
Sign in to the AWS IAM console.
Create (or choose) an IAM user dedicated to this connector. The connector signs requests with a static access key, and only IAM users have access keys.
Attach a policy granting the actions below. EKS grants each action on a different resource, so scope every statement to the resource type the action requires. An action scoped to the wrong resource type is denied.
- All resources (
"Resource": "*"):eks:ListClustersandeks:ListAccessPolicies. These actions don't support resource-level permissions. The connector test callsListClusters, so a policy that scopes it to cluster ARNs fails the test. - Clusters (
arn:aws:eks:<region>:<account-id>:cluster/<cluster-name>):eks:DescribeCluster,eks:ListNodegroups,eks:ListUpdates,eks:DescribeUpdate,eks:ListTagsForResource,eks:ListAccessEntries,eks:UpdateClusterConfig(used by bothupdateClusterConfigandupdateClusterAccessConfig),eks:CreateAccessEntry. - Node groups (
arn:aws:eks:<region>:<account-id>:nodegroup/<cluster-name>/*):eks:DescribeNodegroup,eks:UpdateNodegroupConfig, andeks:ListTagsForResource,eks:ListUpdates,eks:DescribeUpdatefor node group tags and updates. - Access entries (
arn:aws:eks:<region>:<account-id>:access-entry/<cluster-name>/*):eks:DescribeAccessEntry,eks:ListAssociatedAccessPolicies,eks:UpdateAccessEntry,eks:DeleteAccessEntry,eks:AssociateAccessPolicy,eks:DisassociateAccessPolicy.
Leave out the write actions you don't want the connector to perform.
updateNodegroupConfig,updateClusterAccessConfig, andupdateAccessEntryalso read the current node group, cluster, or access entry first, so they needeks:DescribeNodegroup,eks:DescribeCluster, oreks:DescribeAccessEntry.getTokenneeds no extra IAM permission (sts:GetCallerIdentityis always allowed), but the identity must have an access entry on the cluster for the token to be accepted.- All resources (
Create an access key for that user (Security credentials → Access keys → Create access key).
Copy the Access key ID and Secret access key, and enter them along with the AWS Region when configuring the connector in Kibana.