Amazon EKS enhances cluster governance with new IAM condition keys
Share
Services
[Amazon Elastic Kubernetes Service](https://aws.amazon.com/eks/) (EKS) now supports seven additional [IAM condition keys](https://docs.aws.amazon.com/service-authorization/latest/reference/list%5Famazonelastickubernetesservice.html#amazonelastickubernetesservice-policy-keys) for cluster creation and configuration APIs, enhancing the governance controls available through IAM policies and Service Control Policies (SCPs). Organizations managing multi-account environments require centralized mechanisms to enforce security and compliance requirements consistently across all clusters without relying on manual processes or post-deployment checks. This expansion of EKS IAM condition keys further enables proactive policy enforcement, providing organizations with more granular control to establish guardrails for cluster configurations.
Organizations can now enforce private-only API endpoints (eks:endpointPublicAccess, eks:endpointPrivateAccess), require customer-managed AWS KMS keys for secrets encryption (eks:encryptionConfigProviderKeyArns), restrict clusters to approved Kubernetes versions (eks:kubernetesVersion), mandate deletion protection for production workloads (eks:deletionProtection), specify control plane scaling tiers (eks:controlPlaneScalingTier), and enable zonal shift capabilities for high availability (eks:zonalShiftEnabled). These condition keys apply to CreateCluster, UpdateClusterConfig, UpdateClusterVersion, and AssociateEncryptionConfig APIs, integrating seamlessly with AWS Organizations SCPs for centralized governance across accounts.
The new IAM condition keys are available in all AWS Regions where Amazon EKS is available at no additional charge. To learn more about Amazon EKS IAM condition keys, see the Amazon EKS [User Guide](https://docs.aws.amazon.com/eks/latest/userguide/security-iam-service-with-iam.html#security-iam-service-with-iam-id-based-policies) and the [Service Authorization Reference](https://docs.aws.amazon.com/service-authorization/latest/reference/list%5Famazonelastickubernetesservice.html) for Amazon EKS. For information about implementing Service Control Policies, see the [AWS Organizations documentation](https://docs.aws.amazon.com/organizations/latest/userguide/orgs%5Fmanage%5Fpolicies%5Fscps.html).
What else is happening at Amazon Web Services?
Read update
Services
Share
Amazon EBS expands volume modification enhancement to AWS European Sovereign Cloud Region
about 14 hours ago
Services
Share
AWS IoT Greengrass v2.17 now supports non-root installation and introduces new light weight components
about 16 hours ago
Services
Share
Amazon DocumentDB (with MongoDB compatibility) now supports in-place upgrade from version 5.0 to 8.0
about 17 hours ago
Services
Share
Amazon Connect outbound campaigns now supports hourly segment refresh
about 18 hours ago
Services
Share
Read update
Services
Share