awslabs / awslabs/amazon-eks-ami

Add pre-built FIPS AMI

Open
#1,002 20 comments 74 reactions 0 assignees View on GitHub
enhancement never-stale
Dominant language
Go
Stars
2.7k
Forks
1.2k
Avg merge
2d 46m
Merged PRs (30d)
18

Description

**What would you like to be added**:
I'd like to be able to use a pre-built FIPS version of the AL2 EKS AMI provided by Amazon; AFAIK the spec for this is described in this [blog](https://aws.amazon.com/blogs/publicsector/enabling-fips-mode-amazon-linux-2/). I think this is required for both AMD64 & ARM64 but AMD64 support would do for now. I'd suggest the AMI name prefix of `amazon-eks-fips-node-`.

**Why is this needed**:
Everyone needing FIPS nodes needs to do the exact same thing which is the definition of toil and it should be easy to automate this as part of the AMI release process.

Contributor guide

Open the contributing guide

Research direction

Start by locating the repository's Packer configuration and AMI release process, then compare the existing AL2 EKS AMI setup with the FIPS requirements in the linked AWS blog. Done means the release process produces a pre-built FIPS AMI with the proposed naming and at least AMD64 support.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, linux
Domain
cloud, infrastructure, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.