Plan EKS Deployment
VPC
- Secondary IP
- Firewall rules
- Private endpoints
- Transit gateway
- Internal network access via VPN/Bastion
EKS
- EKS Auto mode
- Authentication via EKS access entries
- Karpenter nodepools (System?)
- Certificate management
- Secrets management
- Secret stores location: central/distributed
- Secrets policy and secret stores
- Secrets store structure
- ECR registry
- Single registry?
- Policies for images
- ECR creation and access process
- DNS
- Domain names with multi-region view
- External DNS automation
- KMS
- Cross-account may require additional work
- Service mesh considered?
- EBS volumes
- Custom storage class enforcing encryption
DevOps
- Image build process
- Application packaging — Helm?
- Release method
- Load testing on EKS nodes?
- Workflows (Argo Workflows?)
- GitHub runners?
- GitHub OIDC
- Argo CD application sets?
Dev
- Access to cluster and permissions