Amazon EKS
Amazon EKS
Customer Account
Kubectl mycluster.eks.amazonaws.com
AZ 1 AZ 2 AZ 3
EKS Workers
https://github.com/aws/amazon-vpc-cni-k8s
© 2018, Amazon Web Services, Inc. or its affiliates. All rights
reserved.
ec2.associateaddress()
ENI
Secondary IPs:
10.0.0.20
10.0.0.22 Nginx Pod
Nginx Pod
Veth IP: 10.0.0.20
Veth IP: 10.0.0.1
Secondary IPs:
Java Pod 10.0.0.1
Java Pod
Veth IP: 10.0.0.2 10.0.0.2
Veth IP: 10.0.0.22
Isolate dev, test, and prod E.g., typically use namespaces Reduce attack surface within E.g., PCI, HIPAA
for different teams within microservice-based applications
a company—but without
network policy, they are
not network isolated
AWS
CloudTrail
Amazon
CloudWatch
Master
Version Version
1.10 1.9.2 1.9.1 1.9
Demo 操作演示