Part 4 · Fundamentals

EKS responsibility boundaries and compute choices

Prerequisites: 01-control-loops

04 / Managed does not mean ownerless

A responsibility matrix compares standard EKS, managed node groups, Auto Mode and Fargate across AWS and team responsibilities.

Scroll the diagram sideways for readable labels.

Responsibility summary, not a full service contract. Self-managed and Hybrid Nodes are additional options. EKS control plane reliability and application reliability are different layers. [S14] [S15] [S16] [S37]

Learning objective and mental model verified

EKS supplies a managed Kubernetes control plane. AWS documents control-plane operation across three Availability Zones. Workload replicas, dependency resilience and application recovery still require design; a highly available API server does not make a single application replica highly available.

[S14] [S37]

Compute decision verified

Managed node groups simplify EC2 node provisioning and lifecycle operations. Self-managed nodes give more control and more maintenance. Auto Mode extends managed operation into compute autoscaling, networking, load balancing and block storage. Hybrid Nodes cover supported non-AWS compute environments. These are ownership choices, not application availability guarantees.

[S16] [S15]

Fargate boundary verified

Fargate provides per-Pod compute without managing EC2 worker instances. EKS Fargate does not support DaemonSets, privileged containers or GPUs; it uses private subnets and IP load-balancer targets. EBS cannot be mounted to Fargate Pods. EFS support has separate provisioning constraints.

[S30] [S21] [S29]

Worked example and trade-off synthesis

For a typical API with custom node agents, a managed node group may be easier to integrate than Fargate. Auto Mode is a candidate when supported defaults fit and reducing node operations matters. This is a conditional judgment: validate storage classes, IAM, agent support and disruption behavior before choosing.

[S15] [S16] [S30]

Pitfall and further improvement synthesis

“Managed” is not a universal promise of zero maintenance. Write a responsibility matrix for node releases, add-ons, identity, backups, alerts and workload compatibility. Review it whenever compute mode changes.

[S15] [S37]
Keep this: Select how much infrastructure AWS operates, without giving away application ownership.
Check yourself: Will Auto Mode make an application with one replica resilient to every node replacement?

No. It manages infrastructure lifecycle; your workload still needs suitable replication, disruption tolerance and resilient dependencies.

Sources & further reading

  1. [S14] What is Amazon EKS?

    AWS · documentation · accessed 2026-10-10 · Living documentation; target-cluster compatibility must be checked · Not stated in retrieved page

    Supports: Managed Kubernetes and AWS integration

    Read the linked primary source for implementation details and current constraints.

  2. [S15] EKS Auto Mode

    AWS · documentation · accessed 2026-10-10 · Living documentation; target-cluster compatibility must be checked · Not stated in retrieved page

    Supports: Managed compute, networking, load balancing and block storage

    Read the linked primary source for implementation details and current constraints.

  3. [S16] EKS compute options

    AWS · documentation · accessed 2026-10-10 · Living documentation; target-cluster compatibility must be checked · Not stated in retrieved page

    Supports: Auto Mode, managed nodes, self-managed nodes, Fargate, Hybrid Nodes

    Read the linked primary source for implementation details and current constraints.

  4. [S21] EBS CSI integration

    AWS · documentation · accessed 2026-10-10 · Living documentation; target-cluster compatibility must be checked · Not stated in retrieved page

    Supports: EBS support limits and different Auto Mode provisioner

    Read the linked primary source for implementation details and current constraints.

  5. [S29] EFS CSI integration

    AWS · documentation · accessed 2026-10-10 · Living documentation; target-cluster compatibility must be checked · Not stated in retrieved page

    Supports: Shared filesystem integration and Fargate static provisioning constraint

    Read the linked primary source for implementation details and current constraints.

  6. [S30] AWS Fargate for EKS

    AWS · documentation · accessed 2026-10-10 · Living documentation; target-cluster compatibility must be checked · Not stated in retrieved page

    Supports: No DaemonSets, privileged containers or GPUs; private subnets and IP targets

    Read the linked primary source for implementation details and current constraints.

  7. [S37] EKS reliability

    AWS · documentation · accessed 2026-10-10 · Living documentation; target-cluster compatibility must be checked · Not stated in retrieved page

    Supports: Control plane across three AZs; shared data plane responsibility

    Read the linked primary source for implementation details and current constraints.