Production EKS Platform — From Zero to Production›Part 3 · Cheat sheet & self-check

Part 3 — Operate · wrap-up

Cheat sheet & self-check

17 questions across 5 lessons. Each answer links back to the lesson it came from.

Pick an answer to see if you got it, and why.

  1. Q1. Which EKS control-plane log types matter most for security investigations?

    Show answer

    B. Audit logs record every API request; authenticator logs show how IAM identities were authenticated. Both are off until you enable them.

    From lesson 11 · Observability: Prometheus, Grafana & CloudWatch
  2. Q2. What's the main trade-off between self-run Prometheus and Amazon Managed Service for Prometheus?

    Show answer

    B. Both speak PromQL. The decision is operational effort versus usage-based cost and control.

    From lesson 11 · Observability: Prometheus, Grafana & CloudWatch
  3. Q3. Why alert on symptoms (error rate, latency) rather than causes (CPU high)?

    Show answer

    B. Page on SLO burn and user-visible symptoms; keep cause metrics on dashboards for diagnosis.

    From lesson 11 · Observability: Prometheus, Grafana & CloudWatch
  4. Q4. A surprise CloudWatch bill appears after enabling logging. Most likely cause?

    Show answer

    B. Log ingestion and storage are priced per GB. Filter noisy logs, set retention on log groups, and consider cheaper tiers or S3 for bulk logs.

    From lesson 11 · Observability: Prometheus, Grafana & CloudWatch
  5. Q5. Under the shared-responsibility model on EKS, who patches the worker node OS?

    Show answer

    B. AWS secures the control plane. With managed node groups you still choose when to roll to new AMIs; Fargate and Auto Mode move node patching to AWS.

    From lesson 12 · Security: KMS, GuardDuty, IMDSv2, Pod Security & network policy
  6. Q6. What does the restricted Pod Security Standard block?

    Show answer

    B. restricted is the hardened profile. Enforce it per namespace with a label; use baseline or exemptions only where a component genuinely needs more.

    From lesson 12 · Security: KMS, GuardDuty, IMDSv2, Pod Security & network policy
  7. Q7. Where should application secrets come from?

    Show answer

    B. Keep secrets out of Git and out of manifests. The source of truth lives in a managed secret store with access controlled by IAM and audited by CloudTrail.

    From lesson 12 · Security: KMS, GuardDuty, IMDSv2, Pod Security & network policy
  8. Q8. What does GuardDuty add for EKS?

    Show answer

    B. GuardDuty flags things like anonymous API access, known-malicious IPs, crypto-mining and suspicious container behaviour.

    From lesson 12 · Security: KMS, GuardDuty, IMDSv2, Pod Security & network policy
  9. Q9. What's the right order for an EKS upgrade?

    Show answer

    B. Nodes must never be newer than the control plane, and add-ons must match the new version. Upgrades go one minor at a time.

    From lesson 13 · Upgrades & add-ons
  10. Q10. How does Karpenter roll nodes onto a new AMI or version?

    Show answer

    B. Change the AMI selection (or let a pinned alias move), and drift replaces nodes respecting PDBs and disruption budgets.

    From lesson 13 · Upgrades & add-ons
  11. Q11. When is a blue/green cluster upgrade worth the extra effort?

    Show answer

    B. A new cluster built from code, with traffic shifted gradually, gives a clean rollback path. In-place is simpler for routine minor upgrades.

    From lesson 13 · Upgrades & add-ons
  12. Q12. Someone ran 'terraform destroy' in the wrong workspace, and the state now shows nothing, but the resources were only partly deleted. First step?

    Show answer

    B. Acting fast without understanding can make it worse. Freeze changes, preserve evidence, compare state with reality, then recover.

    From lesson 14 · Disaster recovery
  13. Q13. Why does versioning on the state bucket matter?

    Show answer

    B. Versioning is the undo button for state. Combine it with locking and restricted access.

    From lesson 14 · Disaster recovery
  14. Q14. What lets you rebuild an EKS cluster's workloads quickly after losing the cluster?

    Show answer

    B. EKS doesn't give you etcd snapshots; your recovery path is declarative code plus data backups.

    From lesson 14 · Disaster recovery
  15. Q15. How does kubectl authenticate to EKS after `aws eks update-kubeconfig`?

    Show answer

    B. No long-lived secrets in the kubeconfig; access follows your IAM session.

    From lesson 15 · The flow: laptop → cluster → app
  16. Q16. In the CI/CD way of working, who writes to production?

    Show answer

    B. Changes become reviewed, logged and repeatable.

    From lesson 15 · The flow: laptop → cluster → app
  17. Q17. Why push images by digest and deploy the digest?

    Show answer

    B. See GitHub Actions — Level by Level, lesson 07.

    From lesson 15 · The flow: laptop → cluster → app