aws / aws/containers-roadmap

[EKS] [request]: Integrated Policy Enforcement

Open
#1,435 3 comments 11 reactions 0 assignees View on GitHub
EKS Proposed
Dominant language
Shell
Stars
5.4k
Forks
334
PR merge metrics
No merged PRs in 30d

Description

Hi Everyone,

We are looking to get input on your experiences and opinions on policy definition and enforcement with EKS. Your feedback will be valuable and help us to build a more integrated product experience for policy enforcement.

Some questions that we have are:
- Are you performing policy enforcement today?
- If no, why not?
- If yes, what kind of policies are you applying (pods must have resource requests, pods can't use host networking, pods can't use persistent volumes, etc)
- If yes, are you applying policies to meet security and compliance requirements, or simply limit what developers can do in a cluster?
- What tool(s) are you using for policy enforcement? (Kyverno, OPA/Gatekeeper, still using Pod Security Policies, other)
- Are you actively blocking pods from being scheduled, or only logging warnings?
- Are you configuring mutating or validating policies?
- If using GitOps, do you perform any policy evaluation at commit time, or only at runtime when manifests are applied to a cluster?
- Within you organization, are policy standards defined and written by a centralized group or by decentralized teams?
- Are you doing Kubernetes Network Policy enforcement?
- If yes, what tool(s) are you using? (Calico, Cilium, etc)
- Do you use any other AWS services like AWS Config for any non Kubernetes policy enforcement today?
- What challenges are you experiencing with policy enforcement? Any other feedback?

Looking forward to hearing from everyone!

Contributor guide

Open the contributing guide

Research direction

No files, tests, or implementation entry points are identified. Start by reviewing the policy-enforcement questions in the issue and the existing discussion, then determine whether the requested feedback has become a defined product scope; done would require an agreed implementation direction rather than a localized code change.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, kubernetes
Domain
cloud, infrastructure, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.