Q74Design Secure Architectures
A company is moving an application from an on-premises environment to Amazon Elastic Kubernetes Service (Amazon EKS). To meet requirements, the company must use a custom subnet for pods in the company’s VPC. The company must also ensure that pods can communicate securely within the pods’ VPC. Which solution meets these requirements?
← → navigate · a answer
Community votes
Discussion · 5
C 8
The Amazon VPC Container Network Interface (CNI) plugin is the default network plugin for Amazon EKS. It allows Kubernetes pods to receive IP addresses from a VPC's subnet and enables pods to communicate securely within the VPC as if they were native VPC resources.
C 3
Probably C
https://repost.aws/knowledge-center/eks-custom-subnet-for-pod
C 2
C all the way.
C 1
A - AWS Transit Gateway is used to manage connectivity between multiple VPCs, on-premises networks, or other AWS services. It does not manage pod-level subnet configurations in Amazon EKS.
B - This can't address the specific requirement to configure custom subnets for pods within the VPC.
C - This is the recommended approach.
D - Pod anti-affinity rules are used for scheduling constraints, not for subnet allocation or secure communication within the VPC.
C 1
The Amazon VPC CNI plugin is a Kubernetes networking plugin for EKS.
where it provides: a unique VPC IP address for each pod and native integration of Kubernetes networking into AWS VPC
- Pods can communicate like any EC2 instance on the same subnet.