Production EKS Platform — From Zero to Production›Part 1 · Cheat sheet & self-check

Part 1 — Foundations · wrap-up

Cheat sheet & self-check

7 questions across 2 lessons. Each answer links back to the lesson it came from.

Pick an answer to see if you got it, and why.

  1. Q1. Which part of an EKS cluster does AWS operate for you?

    Show answer

    B. EKS runs and scales the control plane across AZs. You own the data plane (nodes or Fargate), add-on configuration and everything you deploy.

    From lesson 01 · AWS & EKS services and terms
  2. Q2. What's the difference between an access entry and Pod Identity?

    Show answer

    B. Two directions: IAM principal → Kubernetes (access entries), and Kubernetes ServiceAccount → IAM role (Pod Identity or IRSA).

    From lesson 01 · AWS & EKS services and terms
  3. Q3. Why do most EKS worker nodes live in private subnets?

    Show answer

    B. Keeping nodes private shrinks the attack surface. Public subnets hold internet-facing load balancers and NAT gateways.

    From lesson 01 · AWS & EKS services and terms
  4. Q4. What is an EKS managed add-on?

    Show answer

    B. Managed add-ons are versioned and updated through the EKS API, with compatibility checks against the cluster version.

    From lesson 01 · AWS & EKS services and terms
  5. Q5. In EKS, who operates etcd and the API servers?

    Show answer

    B. AWS runs, scales, patches and backs up the control plane. You own the data plane, add-ons, workloads, IAM and networking design.

    From lesson 02 · EKS architecture & mental model
  6. Q6. What happens if you stay on a Kubernetes version after its standard support ends?

    Show answer

    B. EKS versions have standard support, then paid extended support. Planning regular upgrades avoids both cost and forced upgrades.

    From lesson 02 · EKS architecture & mental model
  7. Q7. Which data-plane option launches right-sized EC2 nodes directly for pending pods, without predefined node groups?

    Show answer

    B. Karpenter reads pending pods' requirements and provisions matching instances, then consolidates. Node groups scale predefined ASGs.

    From lesson 02 · EKS architecture & mental model