Skip to main content

Amazon EKS for Cloud Engineers

Learn Amazon EKS end to end: create clusters with eksctl and Terraform, give pods AWS access, add load balancers and storage, and upgrade safely.

~4.5 hours
14 Topics
Hands-on Scenarios

What You'll Learn

Understanding What Amazon EKS Manages and What You Own

It is 11:40 on a Friday night at acme-shop.

Preparing Your Workstation and AWS Account for EKS

Most failed EKS labs fail before the first command that matters: an old kubectl, a missing tool, or credentials for the wrong account.

Creating an EKS Cluster with eksctl

eksctl is the official command-line tool for EKS.

Building the Same Cluster with Terraform

eksctl is the fastest way to learn. Terraform is how most teams keep EKS clusters long term, because the cluster, VPC, IAM roles, and DNS all live in...

Choosing Compute: Managed Node Groups, Fargate, Karpenter, and Auto Mode

Pods need somewhere to run. EKS offers four ways to provide that compute, and the choice decides how much node management you do, how fast scaling...

Controlling Who Can Use the Cluster with Access Entries

Every kubectl call to EKS is authenticated with IAM and then authorized by Kubernetes.

Skills You'll Master

EKSKUBERNETESAWSEKSCTLPOD-IDENTITY

Curriculum Index14 topics

1

Understanding What Amazon EKS Manages and What You Own

It is 11:40 on a Friday night at acme-shop.

2

Preparing Your Workstation and AWS Account for EKS

Most failed EKS labs fail before the first command that matters: an old kubectl, a missing tool, or credentials for the...

3

Creating an EKS Cluster with eksctl

eksctl is the official command-line tool for EKS.

4

Building the Same Cluster with Terraform

eksctl is the fastest way to learn. Terraform is how most teams keep EKS clusters long term, because the cluster, VPC...

5

Choosing Compute: Managed Node Groups, Fargate, Karpenter, and Auto Mode

Pods need somewhere to run. EKS offers four ways to provide that compute, and the choice decides how much node...

6

Controlling Who Can Use the Cluster with Access Entries

Every kubectl call to EKS is authenticated with IAM and then authorized by Kubernetes.

7

Giving Pods AWS Access with EKS Pod Identity

Pods often need AWS APIs: cart-service reads S3, a worker reads SQS, the EBS driver creates volumes.

8

Exposing Applications with the AWS Load Balancer Controller

A Kubernetes Service of type ClusterIP is only reachable inside the cluster.

9

Adding Persistent Storage with the EBS CSI Driver

Containers lose their files when they restart.

10

Upgrading EKS Clusters Safely

Kubernetes releases a new minor version roughly three times a year, and EKS follows.

11

Controlling EKS Cost and Tearing Down Cleanly

EKS cost surprises come from three places: resources running when nobody needs them, resources created by Kubernetes...

12

Running the Lab: Building and Exposing cart-service on EKS

In this lab you build acme-shop's first EKS cluster, put cart-service behind a real ALB, give it persistent storage...

13

Running the Lab: Storage, Pod Access, and Teardown

The cluster from the previous topic is still running and billing, so continue straight on.

14

Reviewing EKS: Quick Reference, Common Mistakes, and Next Steps

Quick reference Common mistakes Putting application permissions on the node role.

Career Impact

Roles that use the skills in this module.

  • DevOps Engineer

  • Site Reliability Engineer

  • Platform Engineer

  • Cloud Engineer

See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

No. Every EKS cluster pays an hourly control plane fee from the moment it exists, plus the EC2 nodes, NAT gateway, and load balancers it uses. A short lab costs a few US dollars if you delete the cluster the same day, and much more if you forget it.

Learn eksctl first because it shows you every moving part with one config file. Use Terraform for clusters your team keeps, because it versions the whole stack, VPC included, next to the rest of your infrastructure.

Both give a pod its own IAM role instead of borrowing the node's role. Pod Identity is the newer method: no OIDC provider per cluster and a simpler trust policy. IRSA is the older method you will still meet, and it is the one that works on Fargate.

Each Kubernetes version gets 14 months of standard support on EKS, then 12 months of extended support at a much higher hourly price. In practice, plan one minor version upgrade every few months so you never fall into extended support by accident.