aws / aws/containers-roadmap

[EKS] [request]: Updating managed node groups with a new cidr block in lunch template for SSH allow list IPs

Open
#1,628 0 comments 1 reaction 0 assignees View on GitHub
EKS EKS Managed Nodes Proposed
Dominant language
Shell
Stars
5.4k
Forks
334
PR merge metrics
No merged PRs in 30d

Description

### Community Note

* Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
* If you are interested in working on this issue or have submitted a pull request, please leave a comment

**Tell us about your request**
Want to request EKS node group SSH Access can not only update security group but also can update allowed cidr block directly.

**Which service(s) is this request for?**
EKS

**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
need to have some shared basions for differenet clients (accounts) to ssh into the ESK worknode, currently can only allow remote access by updating security group, but it's a little bit burden if need to replace the new security group's 0.0.0.0/0:22 rules then add new desired cidr blocked, it's not quite intuitive for auto deployment.

**Are you currently working around this issue?**
like above description.

**Additional context**
Anything else we should know?

**Attachments**
If you think you might have additional information that you'd like to include via an attachment, please do - we'll take a look. (Remember to remove any personally-identifiable information.)
![image](https://user-images.githubusercontent.com/10775909/149814938-7ffe9d32-4aa4-4434-9533-108033c8e5ec.png)

Contributor guide

Open the contributing guide

Research direction

No source files or tests are named; start by clarifying the EKS managed node group and launch-template behavior described in the request, including how SSH allow-list CIDR blocks should be updated. Done requires an agreed, precise scope for changing CIDR access without manually replacing security-group rules.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, kubernetes
Domain
cloud, infrastructure, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.