aws / aws/containers-roadmap

[EKS] [request]: Outbound traffic come from a single ip for whitelisting in public subnets

Open
#1,519 0 comments 1 reaction 0 assignees View on GitHub
EKS Proposed
Dominant language
Shell
Stars
5.4k
Forks
334
PR merge metrics
No merged PRs in 30d

Description

Hello, running EKS with EC2 worker group all in public subnets in the VPC. Is it even possible to make outbound requests from inside of pods appear to come from a static ip address to whitelist? Typically this is done using a NAT Gateway, but my understanding this is only possible in private subnets. The EKS cluster is in production, so rebuilding the entire thing and assigning worker nodes into private subnets instead of public subnets is not possible. Any clever tricks or using Squid?

```
EKS Kubernetes version: 1.20
Platform version: eks.2
```

Contributor guide

Open the contributing guide

Research direction

No repository files, tests, or entry points are mentioned. Start by reviewing the EKS 1.20 networking setup described in the issue, including public-subnet worker nodes and outbound pod traffic; done would require a maintainer-confirmed supported approach for a static outbound IP without rebuilding the cluster.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, kubernetes
Domain
cloud, infrastructure, networking
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.