Cheat Sheets / Cloud — OpenStack, AWS & EKS

Production EKS Platform cheat sheet

114 commands from every lesson of Production EKS Platform — From Zero to Production, on one page.

01 · AWS & EKS services and terms

Look around an account

aws sts get-caller-identityWhich account and role am I using?
aws ec2 describe-availability-zones --query 'AvailabilityZones[].ZoneName'AZs in the current region
aws ec2 describe-vpcs --query 'Vpcs[].[VpcId,CidrBlock]' --output tableVPCs and their CIDRs
aws eks list-clustersEKS clusters in this region
aws eks describe-cluster --name prod --query 'cluster.[version,status,endpoint]'Version, status and API endpoint
aws eks list-addons --cluster-name prodManaged add-ons installed
aws service-quotas list-service-quotas --service-code eksEKS service quotas

02 · EKS architecture & mental model

Inspect a cluster

aws eks list-clustersClusters in the region
aws eks describe-cluster --name prod --query 'cluster.[version,status,endpoint,resourcesVpcConfig.endpointPublicAccess,resourcesVpcConfig.endpointPrivateAccess]'Version, status, endpoint access
aws eks update-kubeconfig --name prod --region eu-west-1Add the cluster to your kubeconfig
aws eks list-addons --cluster-name prodInstalled EKS add-ons
aws eks list-nodegroups --cluster-name prodManaged node groups

03 · AWS account & VPC for EKS

Inspect the network

aws ec2 describe-subnets --filters Name=vpc-id,Values=<vpc> --query 'Subnets[].[SubnetId,AvailabilityZone,CidrBlock,AvailableIpAddressCount]' --output tableSubnets, AZs and free IPs
aws ec2 describe-route-tables --filters Name=vpc-id,Values=<vpc>Routes (IGW for public, NAT for private)
aws ec2 describe-nat-gateways --filter Name=vpc-id,Values=<vpc>NAT gateways per AZ
aws ec2 describe-vpc-endpoints --filters Name=vpc-id,Values=<vpc>Private endpoints to AWS services
aws ec2 describe-subnets --filters Name=tag:kubernetes.io/role/internal-elb,Values=1Subnets marked for internal load balancers

04 · VPC CNI & IP planning

Inspect

kubectl -n kube-system get ds aws-node -o jsonpath='{.spec.template.spec.containers[0].env}' | jqVPC CNI settings (env vars)
kubectl get nodes -o custom-columns=NAME:.metadata.name,PODS:.status.allocatable.podsMax pods per node
aws ec2 describe-subnets --subnet-ids <id> --query 'Subnets[].AvailableIpAddressCount'Free IPs left in a subnet

Key settings

ENABLE_PREFIX_DELEGATION=trueAssign /28 prefixes to ENIs (more pods per node)
AWS_VPC_K8S_CNI_CUSTOM_NETWORK_CFG=truePods use subnets from ENIConfig (e.g. a secondary CIDR)
WARM_IP_TARGET / WARM_PREFIX_TARGETHow many spare IPs/prefixes each node keeps ready

05 · The EKS cluster: control plane, compute & add-ons

Cluster

eksctl create cluster -f cluster.yamlCreate a cluster from a config file (quick labs)
aws eks update-kubeconfig --name prod --region eu-west-1Write a kubeconfig entry for the cluster
aws eks describe-cluster --name prod --query 'cluster.resourcesVpcConfig'Endpoint access, subnets, security groups
aws eks update-cluster-config --name prod --resources-vpc-config endpointPublicAccess=false,endpointPrivateAccess=trueMake the API endpoint private

Compute

aws eks list-nodegroups --cluster-name prodManaged node groups
kubectl get nodes -L eks.amazonaws.com/nodegroup,node.kubernetes.io/instance-type,topology.kubernetes.io/zoneNodes with group, type and AZ
aws eks list-fargate-profiles --cluster-name prodFargate profiles

Add-ons

aws eks describe-addon-versions --addon-name vpc-cni --kubernetes-version 1.33Compatible add-on versions for a Kubernetes version
aws eks create-addon --cluster-name prod --addon-name eks-pod-identity-agentInstall a managed add-on
aws eks describe-addon --cluster-name prod --addon-name coredns --query 'addon.[addonVersion,status]'Installed version and health

06 · IAM & governance: access entries, Pod Identity, IRSA, policies

Cluster access (access entries)

aws eks describe-cluster --name prod --query cluster.accessConfigAuthentication mode
aws eks list-access-entries --cluster-name prodWho has access
aws eks create-access-entry --cluster-name prod --principal-arn <role-arn>Grant an IAM role access
aws eks associate-access-policy --cluster-name prod --principal-arn <role-arn> --policy-arn arn:aws:eks::aws:cluster-access-policy/AmazonEKSViewPolicy --access-scope type=namespace,namespaces=shopView access to one namespace
aws eks list-associated-access-policies --cluster-name prod --principal-arn <role-arn>What a principal can do
kubectl auth can-i --list -n shopYour own effective Kubernetes permissions

Pod permissions

aws eks create-pod-identity-association --cluster-name prod --namespace shop --service-account orders --role-arn <role-arn>Give a ServiceAccount an IAM role (Pod Identity)
aws eks list-pod-identity-associations --cluster-name prodAll Pod Identity associations
aws eks describe-cluster --name prod --query cluster.identity.oidc.issuerOIDC issuer (for IRSA)
kubectl annotate sa orders -n shop eks.amazonaws.com/role-arn=<role-arn>IRSA: link a ServiceAccount to a role
kubectl run awscli -n shop --rm -it --image=amazon/aws-cli --overrides='{"spec":{"serviceAccountName":"orders"}}' -- sts get-caller-identityWhich role does a pod really get?

Guard-rails

kubectl get resourcequota,limitrange -n shopQuotas and default limits in a namespace
kubectl label ns shop pod-security.kubernetes.io/enforce=restrictedEnforce the restricted Pod Security Standard
aws service-quotas get-service-quota --service-code ec2 --quota-code L-1216C47ARunning On-Demand standard instance vCPU quota

07 · Ingress: ALB, NLB and the Load Balancer Controller

Controller

helm install aws-load-balancer-controller eks/aws-load-balancer-controller -n kube-system --set clusterName=prodInstall (after creating its IAM role; eks = https://aws.github.io/eks-charts)
kubectl -n kube-system logs deploy/aws-load-balancer-controllerWhy an LB wasn't created
kubectl get ingress,svc -A -o wideLB DNS names on Ingresses and Services

Subnet tags (required for discovery)

kubernetes.io/role/elb = 1Public subnets for internet-facing LBs
kubernetes.io/role/internal-elb = 1Private subnets for internal LBs

08 · ECR & application deployment

ECR

aws ecr create-repository --repository-name shop/api --image-tag-mutability IMMUTABLE --image-scanning-configuration scanOnPush=trueRepository with immutable tags and scan on push
aws ecr get-login-password | docker login --username AWS --password-stdin <acct>.dkr.ecr.<region>.amazonaws.comLog Docker in to ECR (12-hour token)
docker push <acct>.dkr.ecr.<region>.amazonaws.com/shop/api:1.4.0Push an image
aws ecr describe-image-scan-findings --repository-name shop/api --image-id imageTag=1.4.0Vulnerability findings
aws ecr put-lifecycle-policy --repository-name shop/api --lifecycle-policy-text file://lifecycle.jsonExpire old images automatically

Roll out

kubectl set image deploy/api api=<acct>.dkr.ecr.<region>.amazonaws.com/shop/api:1.4.1 -n shopStart a rolling update
kubectl rollout status deploy/api -n shopWatch it complete
kubectl rollout undo deploy/api -n shopRoll back to the previous ReplicaSet
kubectl get pods -n shop -o wide -L topology.kubernetes.io/zoneAre replicas spread across AZs?

09 · Storage: EBS, EFS and S3

Drivers

aws eks create-addon --cluster-name prod --addon-name aws-ebs-csi-driverEBS CSI driver (give it a role via Pod Identity)
aws eks create-addon --cluster-name prod --addon-name aws-efs-csi-driverEFS CSI driver
kubectl get csidriversebs.csi.aws.com, efs.csi.aws.com, …

Tiers

gp3 (WaitForFirstConsumer)Hot: databases, general RWO volumes
io2Hot and demanding: consistent high IOPS
EFS (access points)Shared RWX files across AZs
S3 (+ Mountpoint CSI)Cold, large, read-heavy data; backups

10 · Autoscaling: HPA & Karpenter

Inspect

kubectl get nodepools,ec2nodeclassesKarpenter configuration
kubectl get nodeclaims -o wideNodes Karpenter launched (type, zone, capacity type)
kubectl -n kube-system logs deploy/karpenter -fWhy it launched or removed a node (namespace depends on install)
kubectl get nodes -L karpenter.sh/capacity-type,node.kubernetes.io/instance-type,topology.kubernetes.io/zoneCapacity type, instance type and zone per node

Protect a workload

karpenter.sh/do-not-disrupt: "true"Pod annotation: don't voluntarily disrupt this pod's node
PodDisruptionBudgetKarpenter respects PDBs when draining

11 · Observability: Prometheus, Grafana & CloudWatch

Control plane

aws eks update-cluster-config --name prod --logging '{"clusterLogging":[{"types":["api","audit","authenticator"],"enabled":true}]}'Send control-plane logs to CloudWatch Logs
aws logs tail /aws/eks/prod/cluster --follow --filter-pattern authenticatorFollow control-plane logs
kubectl get --raw /metrics | grep apiserver_request_total | headAPI server metrics (Prometheus format)

In the cluster

aws eks create-addon --cluster-name prod --addon-name amazon-cloudwatch-observabilityContainer Insights + Fluent Bit via managed add-on
helm install kps prometheus-community/kube-prometheus-stack -n monitoring --create-namespaceSelf-run Prometheus, Alertmanager, Grafana
kubectl top pods -A --sort-by=memory | headQuick resource view (metrics-server)

12 · Security: KMS, GuardDuty, IMDSv2, Pod Security & network policy

Check the posture

aws eks describe-cluster --name prod --query 'cluster.[resourcesVpcConfig.endpointPublicAccess,resourcesVpcConfig.publicAccessCidrs,encryptionConfig]'Public endpoint, allowed CIDRs, secrets encryption
aws ec2 describe-launch-templates --query 'LaunchTemplates[].LaunchTemplateName'Find node launch templates to check IMDS settings
kubectl get ns -L pod-security.kubernetes.io/enforcePod Security level per namespace
kubectl get networkpolicy -AWhich namespaces restrict traffic
aws guardduty list-findings --detector-id <id> --finding-criteria '{"Criterion":{"resource.resourceType":{"Eq":["EKSCluster"]}}}'GuardDuty findings for EKS

Harden

kubectl label ns shop pod-security.kubernetes.io/enforce=restricted --overwriteEnforce restricted pods
aws eks update-addon --cluster-name prod --addon-name vpc-cni --configuration-values '{"enableNetworkPolicy":"true"}'Enable network policy in the VPC CNI
trivy image <acct>.dkr.ecr.<region>.amazonaws.com/shop/api:1.4.0Scan an image before deploying

13 · Upgrades & add-ons

Before

aws eks list-insights --cluster-name prodUpgrade insights: deprecated APIs, add-on compatibility and more
aws eks describe-addon-versions --addon-name vpc-cni --kubernetes-version 1.33 --query 'addons[].addonVersions[0].addonVersion'Latest add-on version for the target Kubernetes version
kubectl get pdb -ABudgets that could block node replacement

Do

aws eks update-cluster-version --name prod --kubernetes-version 1.33Upgrade the control plane (or change the version in Terraform)
aws eks update-addon --cluster-name prod --addon-name coredns --addon-version <v>Upgrade an add-on
aws eks update-nodegroup-version --cluster-name prod --nodegroup-name systemRoll a managed node group to the new version

14 · Disaster recovery

State recovery

aws s3api list-object-versions --bucket acme-tfstate-prod --prefix eks/prod/cluster/Previous versions of a state file
aws s3api get-object --bucket … --key … --version-id <id> old.tfstateDownload an older version
terraform state pull > backup.tfstateBack up current state before any repair
import { to = aws_s3_bucket.logs id = "acme-logs" }Re-adopt an existing resource (in code, Terraform 1.5+)

Prevention

lifecycle { prevent_destroy = true }Refuse to plan destruction of critical resources
deletion_protection / termination protectionProvider-level protection where available
IAM deny on eks:DeleteCluster for CI roles (except break-glass)Stop destructive calls at the API

15 · The flow: laptop → cluster → app

Laptop

aws sso login --profile prod-readonlyGet short-lived credentials
aws eks update-kubeconfig --name prod --region eu-west-1 --alias prod --profile prod-readonlyWrite the kubeconfig entry
kubectl config view --minifySee the exec plugin (aws eks get-token)
kubectl auth whoamiWho does the cluster think I am?

Pipelines

infra: OIDC role → terraform plan (PR) / apply (main, approved)Infrastructure changes
app: OIDC role → docker build → push to ECR (by digest)Images
GitOps repo commit → Argo CD syncDeployments

16 · Architecture & design review

Evidence to bring to a review

aws eks describe-cluster --name prodVersion, endpoint access, auth mode, logging, encryption
aws eks list-addons --cluster-name prodManaged add-ons and versions
aws eks list-access-entries --cluster-name prodWho has access
kubectl get nodepools,nodeclaimsKarpenter capacity
kubectl get pdb,hpa -ADisruption budgets and autoscalers
kubectl get ns -L pod-security.kubernetes.io/enforce,teamTenancy and pod security per namespace