Quick reference
Decision tables supplement the illustrated lessons. Follow topic citations for evidence and limits.
Kubernetes concept → AWS integration
| Concept | Typical EKS integration | Decision boundary |
|---|---|---|
| Control plane | Amazon EKS | AWS operates the plane; you operate application contracts. |
| Pod networking | VPC CNI / Auto Mode networking | IP space, policy enforcement and compatible compute matter. |
| Ingress / LoadBalancer Service | ALB / NLB integration | Choose traffic protocol and target/configuration mode. |
| Node capacity | Managed nodes / Karpenter / Auto Mode | Replica scaling and node provisioning remain different loops. |
| Workload identity | Pod Identity / IRSA | Human access and end-user authorization are separate. |
| Persistent storage | EBS / EFS CSI integration | Zone, mount semantics and compute support differ. |
| External durable state | Managed database / object store | Kubernetes orchestration does not replace recovery planning. |
| Cluster access | EKS access entries + RBAC | Grant the minimum required API operations. |
Compute fit
| Option | Useful when | Watch for |
|---|---|---|
| Managed node groups | You want EC2 integration with managed lifecycle tooling. | Your release, add-on and disruption responsibilities. |
| Auto Mode | Supported managed defaults fit and reduce operations. | Mode-specific network/storage contracts and node constraints. |
| Fargate | Compatible per-Pod compute fits. | No DaemonSets, privileged containers, GPU or EBS mounts. |
| Self-managed / Hybrid | Specialized or non-AWS compute is required. | More compatibility, networking and operations work. |
Glossary
| Term | Meaning |
|---|---|
| Pod | One or more containers scheduled together, with shared Pod networking. |
| Node | Compute instance or supported execution surface running Pods. |
| Deployment / ReplicaSet | Release lifecycle / desired replica-count ownership. |
| Namespace | Scope for many Kubernetes API resource names and policies. |
| Service / EndpointSlice | Stable backend abstraction / endpoint descriptions. |
| Ingress / controller | Desired HTTP routing / implementation that realizes it. |
| CNI / CSI / CRI | Networking / storage / container-runtime integration interfaces. |
| PVC / PV / StorageClass | Storage request / allocated volume / provisioning policy. |
| HPA / PDB | Replica scaling / eligible voluntary eviction budget. |
| Request / limit | Scheduling input / runtime resource ceiling. |
| IAM / RBAC | AWS API permissions / Kubernetes API permissions. |
| RPO / RTO | Tolerable recovery data loss / tolerable recovery time. |
Compute evidence · Storage evidence · Identity evidence · Networking evidence