aws / aws/containers-roadmap

[EKS] [request]: Support OPA/Gatekeeper in EKS add-ons

Open
#1,175 2 comments 1 reaction 0 assignees View on GitHub
EKS Proposed
Dominant language
Shell
Stars
5.4k
Forks
334
PR merge metrics
No merged PRs in 30d

Description

### Community Note

* Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
* If you are interested in working on this issue or have submitted a pull request, please leave a comment

**Tell us about your request**
What do you want us to build?
[OPA/Gatekeeper](https://github.com/open-policy-agent/gatekeeper) is used to validate policies across Kubernetes clusters. It is a CNCF incubation-level project and widely adopted by the Kubernetes community. This software is always mentioned when it comes to Kubernetes security best practices. Many other Kubernetes distributions are packaging it and providing support for it out of the box. Would be nice to have it as and EKS add-on so integration tests are done by the AWS team.
**Which service(s) is this request for?**
This could be and EKS add-on

**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
There are some policies which are needed to be followed for security best practices and most of the cases there are other policies to meet corporate compliance requirements. For example "only pull from specific registries", "make sure you have some labels with your deployments".
Arguably, the most widely used tool for ensuring such policies in the kubernetes world is OPA/Gatekeeper. As such, it gets installed on most of the production clusters.

What outcome are you trying to achieve, ultimately, and why is it hard/impossible to do right now? What is the impact of not having this problem solved? The more details you can provide, the better we'll be able to understand and solve the problem.
I try to achieve that integration testing and updates are done by AWS instead of each cluster owner.

**Are you currently working around this issue?**
How are you currently solving this problem?
Installing/maintaining Gatekeeper manually on top of EKS

Contributor guide

Open the contributing guide

Research direction

Start with the EKS add-ons request and the linked OPA/Gatekeeper project to understand the integration surface. Compare the current manual installation and maintenance workaround with the desired AWS-managed integration testing and updates. Done means OPA/Gatekeeper is supported as an EKS add-on with those managed integration and update outcomes.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, kubernetes
Domain
cloud, infrastructure, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.