Amazon EKS Now Supports Service-Linked Roles
Share
Services
Amazon Elastic Kubernetes Service (EKS) now supports using AWS Identity and Access Management (IAM) [service-linked roles](http://docs.aws.amazon.com/IAM/latest/UserGuide/id%5Froles%5Fterms-and-concepts.html#iam-term-service-linked-role) to easily delegate cluster management permissions to EKS.
The EKS service-linked role is predefined by Amazon EKS and includes the permissions that EKS requires to create and manage clusters. Examples include creating the [Amazon Elastic Compute Cloud](/ec2/) (Amazon EC2) cross-account [Elastic Network Interfaces](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html) (ENIs) that facilitate communication to your worker nodes. A service-linked role makes setting up Amazon EKS easier because you don’t have to manually add the necessary permissions.
Unlike a normal IAM role, you cannot delete the service-linked role if it is still in use by an Amazon EKS cluster. This protects from any service downtime or upgrade issues that could result from you inadvertently revoking Amazon EKS's required permissions to manage clusters on your behalf. Actions performed by Amazon EKS against its service-linked role will be logged in [AWS CloudTrail](https://docs.aws.amazon.com/eks/latest/userguide/logging-using-cloudtrail.html).
As of today, the Amazon EKS service-linked role will be used for all new clusters created in [AWS regions](/about-aws/global-infrastructure/regional-product-services/) where Amazon EKS is available. You don't need to manually create a service-linked role. When you create a cluster in the AWS Management Console, the AWS CLI, or the AWS API, Amazon EKS creates the service-linked role for you. To learn more about Amazon EKS and its service linked role, please visit the Amazon EKS [documentation](https://docs.aws.amazon.com/eks/latest/userguide/using-service-linked-roles.html).
What else is happening at Amazon Web Services?
Amazon AppStream 2.0 users can now save their user preferences between streaming sessions
December 13th, 2024
Services
Share
AWS Elemental MediaConnect Gateway now supports source-specific multicast
December 13th, 2024
Services
Share
Amazon EC2 instances support bandwidth configurations for VPC and EBS
December 13th, 2024
Services
Share
AWS announces new AWS Direct Connect location in Osaka, Japan
December 13th, 2024
Services
Share
Amazon DynamoDB announces support for FIPS 140-3 interface VPC and Streams endpoints
December 13th, 2024
Services
Share