aws / aws/containers-roadmap

[EKS] [Audit log]: Allow to custom audit-log policy

Open
#566 55 comments 272 reactions 0 assignees View on GitHub
EKS Proposed
Dominant language
Shell
Stars
5.4k
Forks
334
PR merge metrics
No merged PRs in 30d

Description

**Tell us about your request**
Currently, we could only enable audit log with the default policy. Is it possible to ship audit-log-policy to config map for customization?

**Which service(s) is this request for?**
EKS

**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
Currently, EKS use audit-log with default policy (log all request via kube-api), it causes a huge log to process on our system (most of these logs come from trusted local service). Could we custom audit policy to reduce unnecessary logs?

Contributor guide

Open the contributing guide

Research direction

The request concerns EKS audit logging and asks for a customizable audit-log policy instead of the default policy. Start by reviewing how EKS exposes audit-log configuration and how the requested policy would be supplied through a config map. Done means users can customize the policy and reduce unnecessary audit-log volume.

Written by the indexing model from the issue text.

Assessment

Tech stack
kubernetes
Domain
cloud, observability, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.