Quick reference

Decision tables supplement the illustrated lessons. Follow topic citations for evidence and limits.

Kubernetes concept → AWS integration

ConceptTypical EKS integrationDecision boundary
Control planeAmazon EKSAWS operates the plane; you operate application contracts.
Pod networkingVPC CNI / Auto Mode networkingIP space, policy enforcement and compatible compute matter.
Ingress / LoadBalancer ServiceALB / NLB integrationChoose traffic protocol and target/configuration mode.
Node capacityManaged nodes / Karpenter / Auto ModeReplica scaling and node provisioning remain different loops.
Workload identityPod Identity / IRSAHuman access and end-user authorization are separate.
Persistent storageEBS / EFS CSI integrationZone, mount semantics and compute support differ.
External durable stateManaged database / object storeKubernetes orchestration does not replace recovery planning.
Cluster accessEKS access entries + RBACGrant the minimum required API operations.

Compute fit

OptionUseful whenWatch for
Managed node groupsYou want EC2 integration with managed lifecycle tooling.Your release, add-on and disruption responsibilities.
Auto ModeSupported managed defaults fit and reduce operations.Mode-specific network/storage contracts and node constraints.
FargateCompatible per-Pod compute fits.No DaemonSets, privileged containers, GPU or EBS mounts.
Self-managed / HybridSpecialized or non-AWS compute is required.More compatibility, networking and operations work.

Glossary

TermMeaning
PodOne or more containers scheduled together, with shared Pod networking.
NodeCompute instance or supported execution surface running Pods.
Deployment / ReplicaSetRelease lifecycle / desired replica-count ownership.
NamespaceScope for many Kubernetes API resource names and policies.
Service / EndpointSliceStable backend abstraction / endpoint descriptions.
Ingress / controllerDesired HTTP routing / implementation that realizes it.
CNI / CSI / CRINetworking / storage / container-runtime integration interfaces.
PVC / PV / StorageClassStorage request / allocated volume / provisioning policy.
HPA / PDBReplica scaling / eligible voluntary eviction budget.
Request / limitScheduling input / runtime resource ceiling.
IAM / RBACAWS API permissions / Kubernetes API permissions.
RPO / RTOTolerable recovery data loss / tolerable recovery time.

Compute evidence · Storage evidence · Identity evidence · Networking evidence