View a markdown version of this page

VpcConfigResponse - Amazon EKS

VpcConfigResponse

An object representing an Amazon EKS cluster VPC configuration response.

Contents

clusterSecurityGroupId

The cluster security group that was created by Amazon EKS for the cluster. Managed node groups use this security group for control-plane-to-data-plane communication.

Type: String

Required: No

controlPlaneEgressMode

The current control plane egress routing mode for the cluster. If the cluster is set to AWS_MANAGED, Amazon EKS manages the egress path from the control plane. If the cluster is set to CUSTOMER_ROUTED, you manage the egress path from the control plane in your VPC subnets.

Learn more about control plane egress routing in the Amazon EKS User Guide.

Type: String

Valid Values: AWS_MANAGED | CUSTOMER_ROUTED | CUSTOMER_ISOLATED

Required: No

endpointPrivateAccess

This parameter indicates whether the Amazon EKS private API server endpoint is enabled. If the Amazon EKS private API server endpoint is enabled, Kubernetes API requests that originate from within your cluster's VPC use the private VPC endpoint instead of traversing the internet. If this value is disabled and you have nodes or AWS Fargate pods in the cluster, then ensure that publicAccessCidrs includes the necessary CIDR blocks for communication with the nodes or Fargate pods. For more information, see Cluster API server endpoint in the Amazon EKS User Guide .

Type: Boolean

Required: No

endpointPublicAccess

Whether the public API server endpoint is enabled.

Type: Boolean

Required: No

publicAccessCidrs

The CIDR blocks that are allowed access to your cluster's public Kubernetes API server endpoint. Communication to the endpoint from addresses outside of the CIDR blocks that you specify is denied. The default value is 0.0.0.0/0 and additionally ::/0 for dual-stack `IPv6` clusters. If you've disabled private endpoint access, make sure that you specify the necessary CIDR blocks for every node and AWS Fargate Pod in the cluster. For more information, see Cluster API server endpoint in the Amazon EKS User Guide .

Note that the public endpoints are dual-stack for only IPv6 clusters that are made after October 2024. You can't add IPv6 CIDR blocks to IPv4 clusters or IPv6 clusters that were made before October 2024.

Type: Array of strings

Required: No

securityGroupIds

The security groups associated with the cross-account elastic network interfaces that are used to allow communication between your nodes and the Kubernetes control plane.

Type: Array of strings

Required: No

subnetIds

The subnets associated with your cluster.

Type: Array of strings

Required: No

vpcId

The VPC associated with your cluster.

Type: String

Required: No

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: