[EKS] [feature]: Organizational policy to require add-on
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
### Community Note
* Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
* If you are interested in working on this issue or have submitted a pull request, please leave a comment
**Tell us about your request**
I want to enforce consistent security visibility and governance in our EKS clusters. Having an Organizational policy that requires an add-on be running, similar to how Guardduty EKS Runtime Monitoring will auto-manage the agent if selected, is the desired goal.
**Which service(s) is this request for?**
EKS and ECS
**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
Currently, there's no easy way to get visibility into and apply governance into all clusters in our enterprise. We want to require certain, privileged tooling to run on all clusters.
Contributor guide
Research direction
The issue provides no repository files, tests, or entry points. Start by clarifying whether the scope covers EKS, ECS, or both and how an organizational add-on policy should be defined; done would require an agreed implementation path for enforcing the required tooling across clusters.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, kubernetes
- Domain
- cloud, devops, infrastructure
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100