πΌ [EKS.3] EKS clusters should use encrypted Kubernetes secrets
- Contextual name: πΌ [EKS.3] EKS clusters should use encrypted Kubernetes secrets
- ID:
/frameworks/aws-fsbp-v1.0.0/eks/03
- Located in: πΌ Elastic Kubernetes Service (EKS)
Descriptionβ
When you encrypt secrets, you can use AWS Key Management Service (AWS KMS) keys
to provide envelope encryption of Kubernetes secrets stored in etcd for your cluster.
This encryption is in addition to the EBS volume encryption that is enabled by default
for all data (including secrets) that is stored in etcd as part of an EKS cluster.
Using secrets encryption for your EKS cluster allows you to deploy a defense in depth
strategy for Kubernetes applications by encrypting Kubernetes secrets with a KMS key
that you define and manage.
Similarβ
- AWS Security Hub
- Internal
Similar Sections (Give Policies To)β
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|