Skip to content

Plan EKS Deployment

VPC

  • Secondary IP
  • Firewall rules
  • Private endpoints
  • Transit gateway
  • Internal network access via VPN/Bastion

EKS

  • EKS Auto mode
  • Authentication via EKS access entries
  • Karpenter nodepools (System?)
  • Certificate management
  • Secrets management
    • Secret stores location: central/distributed
    • Secrets policy and secret stores
    • Secrets store structure
  • ECR registry
    • Single registry?
    • Policies for images
    • ECR creation and access process
  • DNS
    • Domain names with multi-region view
    • External DNS automation
  • KMS
    • Cross-account may require additional work
  • Service mesh considered?
  • EBS volumes
    • Custom storage class enforcing encryption

DevOps

  • Image build process
  • Application packaging — Helm?
  • Release method
  • Load testing on EKS nodes?
  • Workflows (Argo Workflows?)
  • GitHub runners?
  • GitHub OIDC
  • Argo CD application sets?

Dev

  • Access to cluster and permissions