[EKS] [request]: Integrated Policy Enforcement
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
Hi Everyone,
We are looking to get input on your experiences and opinions on policy definition and enforcement with EKS. Your feedback will be valuable and help us to build a more integrated product experience for policy enforcement.
Some questions that we have are:
- Are you performing policy enforcement today?
- If no, why not?
- If yes, what kind of policies are you applying (pods must have resource requests, pods can't use host networking, pods can't use persistent volumes, etc)
- If yes, are you applying policies to meet security and compliance requirements, or simply limit what developers can do in a cluster?
- What tool(s) are you using for policy enforcement? (Kyverno, OPA/Gatekeeper, still using Pod Security Policies, other)
- Are you actively blocking pods from being scheduled, or only logging warnings?
- Are you configuring mutating or validating policies?
- If using GitOps, do you perform any policy evaluation at commit time, or only at runtime when manifests are applied to a cluster?
- Within you organization, are policy standards defined and written by a centralized group or by decentralized teams?
- Are you doing Kubernetes Network Policy enforcement?
- If yes, what tool(s) are you using? (Calico, Cilium, etc)
- Do you use any other AWS services like AWS Config for any non Kubernetes policy enforcement today?
- What challenges are you experiencing with policy enforcement? Any other feedback?
Looking forward to hearing from everyone!
Contributor guide
Research direction
No files, tests, or implementation entry points are identified. Start by reviewing the policy-enforcement questions in the issue and the existing discussion, then determine whether the requested feedback has become a defined product scope; done would require an agreed implementation direction rather than a localized code change.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, kubernetes
- Domain
- cloud, infrastructure, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100