Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Amazon EKS networking connects three separate layers: the VPC and subnets that provide address space and routes, the Pod network that assigns addresses to workloads, and the control and traffic paths used to reach the Kubernetes API or an application. The Amazon VPC CNI gives Pods VPC addresses on AWS infrastructure, so IP capacity, address-family choice, endpoint access, traffic controls, and load-balancer design all affect how a cluster works.

What the VPC and subnets provide

An EKS cluster runs in an Amazon VPC. AWS requires at least two subnets in different Availability Zones when creating a cluster, and the VPC needs sufficient IP addresses for the cluster, its nodes, and other Kubernetes resources. Subnet availability is therefore only the starting point: the available address space must also fit expected node and Pod growth.

Plan the VPC’s route tables, security groups, network ACLs, and egress paths around the destinations nodes and Pods must reach. For example, a workload that needs to reach an external service depends on the network path and controls between its subnet and that destination. When connecting the cluster VPC to other VPCs, avoid overlapping address ranges so routing remains unambiguous.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How Pods receive network addresses

On EC2 nodes, the Amazon VPC CNI add-on runs on each node, creates and attaches network interfaces, and assigns VPC addresses to Pods. In the default IPv4 configuration, those are private IPv4 addresses; an IPv6 cluster instead uses IPv6 addresses. AWS describes this as an underlay model: a Pod’s address is consistent from the perspectives of the cluster and the VPC, rather than being hidden behind a separate Pod-only address space.

#1 Best Overall
Sale
TP-Link TL-SG105, 5 Port Gigabit Unmanaged Ethernet Switch, Network Hub, Ethernet Splitter, Plug & Play, Fanless Metal Design, Shielded Ports, Traffic Optimization
  • 𝗢𝗻𝗲 𝗦𝘄𝗶𝘁𝗰𝗵 𝗠𝗮𝗱𝗲 𝘁𝗼 𝗘𝘅𝗽𝗮𝗻𝗱 𝗡𝗲𝘁𝘄𝗼𝗿𝗸: 5× 10/100/1000Mbps RJ45 Ports supporting Auto Negotiation and Auto MDI/MDIX.
  • 𝗚𝗶𝗴𝗮𝗯𝗶𝘁 𝘁𝗵𝗮𝘁 𝗦𝗮𝘃𝗲𝘀 𝗘𝗻𝗲𝗿𝗴𝘆: Latest innovative energy-efficient technology greatly expands your network capacity with much less power consumption and helps save money.
  • 𝗥𝗲𝗹𝗶𝗮𝗯𝗹𝗲 𝗮𝗻𝗱 𝗤𝘂𝗶𝗲𝘁: IEEE 802.3X flow control provides reliable data transfer and Fanless design ensures quiet operation.
  • 𝗣𝗹𝘂𝗴 𝗮𝗻𝗱 𝗣𝗹𝗮𝘆: Easy setup with no software installation or configuration needed.
  • 𝗔𝗱𝘃𝗮𝗻𝗰𝗲𝗱 𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲 𝗙𝗲𝗮𝘁𝘂𝗿𝗲𝘀: Prioritize your traffic and guarantee high quality of video or voice data transmission with Port-based 802.1p/DSCP QoS and IGMP Snooping.

This makes Pod capacity an IP-planning issue as well as a Kubernetes scheduling issue. A cluster can have room to schedule more workloads but still need additional subnet address capacity to support the nodes and Pods those workloads require.

Options when address capacity is tight

  • Plan larger or additional subnet address space. This is the basic capacity decision and should account for node count, Pod scale, and other VPC resources.
  • Prefix delegation. AWS documents it as an option to increase the number of available node addresses. Confirm compatibility and configuration requirements for the specific CNI and node setup rather than assuming it is a drop-in fix.
  • Custom networking and subnet selection. These can direct Pod addresses to selected subnets, but add design and operational considerations; they do not remove the need to plan sufficient address space.
  • IPv6. It changes the address-family design and has compatibility constraints, so it is not simply an extra pool to turn on for an existing cluster.

EKS Auto Mode includes Pod networking and load-balancing capabilities. That changes which capabilities AWS manages compared with a setup where the platform team manages the corresponding add-ons; account for the selected cluster mode when planning ownership and configuration.

Rank #2
NETGEAR 5-Port Gigabit Ethernet Unmanaged Network Switch (GS305)
  • GIGABIT ETHERNET PORTS: Features 5 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
  • PLUG-AND-PLAY UNMANAGED NETWORK SWITCH: Simple plug-and-play setup with no software to install or configuration required.
  • FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
  • SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
  • REGIONAL COMPATIBILITY: Made for use in U.S. & CA only

Choose IPv4 or IPv6 before creating the cluster

EKS assigns IPv4 addresses to Pods and Services by default. The cluster’s IP family is selected at creation and cannot later be changed for that cluster. Moving to a different family therefore means creating another cluster and migrating workloads. EKS does not support dual-stacked Pods or Services.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

IPv6 has additional requirements. AWS documents no Windows support for IPv6 clusters and requires Nitro-based EC2 nodes or Fargate. Check current AWS compatibility requirements for the intended node types and workloads before selecting IPv6. Treat this as a cluster architecture decision, not a setting to defer until after deployment.

Rank #3
Sale
NETGEAR 8-Port Gigabit Ethernet Unmanaged Network Switch (GS308)
  • GIGABIT ETHERNET PORTS: Features 8 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
  • PLUG-AND-PLAY UNMANAGED NETWORK SWITCH: Simple plug-and-play setup with no software to install or configuration required.
  • FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
  • SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
  • REGIONAL COMPATIBILITY: Made for use in U.S. & CA only

Keep Kubernetes API access separate from application traffic

The Kubernetes API server endpoint is the control-plane path used by Kubernetes clients and cluster components. It is not the same endpoint as a Service or Ingress that exposes an application. EKS endpoint access can be public, private, or configured for both, depending on the cluster’s endpoint settings.

When private endpoint access is enabled, EKS creates a Route 53 private hosted zone and associates it with the cluster VPC. The cluster security group’s rules govern access to the private endpoint. In practical terms, a client needs both a network path and permission through the relevant security-group rules to reach that endpoint; exposing an application through a load balancer does not provide Kubernetes API access.

Rank #4
TP-Link 8 Port Gigabit Ethernet Network Switch - Ethernet Splitter | Plug & Play | Fanless | Sturdy Metal w/ Shielded Ports | Traffic Optimization | Unmanaged | Lifetime Protection (TL-SG108)
  • 8 GIGABIT PORTS: Features 8 RJ45 ports supporting 10/100/1000 Mbps speeds, providing high-speed wired network connectivity for computers, printers, gaming consoles, and other Ethernet-enabled devices
  • PLUG AND PLAY SETUP: No configuration required; simply connect the switch to your network devices and it is ready to use immediately, making network expansion quick and hassle-free
  • FANLESS QUIET DESIGN: The fanless design ensures silent operation, making this switch suitable for noise-sensitive environments such as home offices, bedrooms, or conference rooms
  • STURDY METAL CONSTRUCTION: Built with a durable metal housing and shielded ports that provide reliable performance, better heat dissipation, and protection against electromagnetic interference
  • TRAFFIC OPTIMIZATION: Supports IEEE 802.3x flow control and advanced traffic optimization technology to reduce data bottlenecks and ensure smooth, efficient data transfer across your network

AWS introduced dual-stack EKS API endpoints in August 2024 and dual-stack IPv6 cluster endpoints in October 2024. Those endpoint capabilities are distinct from Pod and Service addressing: they do not mean EKS supports dual-stacked Pods or Services.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which traffic controls apply to Pods and AWS resources?

Network policies and security groups for Pods address different scopes. Kubernetes NetworkPolicy is namespace-scoped and controls Pod traffic at the IP and port level. Security groups for Pods apply AWS security-group controls to Pods, including control of access from Pods to AWS services. Neither should be treated as a substitute for understanding the node, VPC, and route paths through which traffic flows.

Best Value
TP-Link LS1005G, Litewave 5 Port Gigabit Ethernet Unmanaged Switch
  • 【One Switch Made to Expand Network】Features 5 RJ45 ports with 10/100/1000Mbps speeds, supporting Auto-Negotiation and Auto MDI/MDIX for hassle-free setup. Ideal for expanding your network, with 1 uplink (input) port and 4 output ports to split your Ethernet connection to multiple devices.
  • 【Gigabit that Saves Energy】Latest innovative energy-efficient technology greatly expands your network capacity with much less power consumption and helps save money
  • 【Reliable and Quiet】IEEE 802.3X flow control provides reliable data transfer and Fanless design ensures quiet operation
  • 【Plug and Play】Easy setup with no software installation or configuration needed
  • 【Ethernet Splitter】Connect to your router or modem for additional wired connections (laptop, gaming console, printer, etc)
Control Primary scope Important qualification
Kubernetes NetworkPolicy Pod-to-Pod and other Pod traffic governed by IP and port rules in a namespace AWS documents VPC CNI support for standard and admin network policies from version 1.21.0. The documented policy support applies to Amazon EC2 Linux nodes, not Fargate or Windows nodes.
Security groups for Pods AWS security-group access control for Pods, including access to AWS services Behavior depends on VPC CNI features, node networking, and add-on configuration. Verify the requirements for the precise use case and CNI version.
VPC and node-level controls Traffic governed by VPC routes, security groups, network ACLs, and egress design These controls shape the broader network path; they do not replace namespace-level Pod segmentation.

Before relying on a policy feature, verify the deployed VPC CNI version and node type. Add-on capabilities are version- and configuration-dependent, and a feature available on EC2 Linux should not be assumed to behave the same way on Fargate or Windows.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How application traffic reaches an EKS workload

For externally reachable applications, Kubernetes resources can provision AWS load balancers. A Service of type LoadBalancer can provision a Network Load Balancer (NLB), while an Ingress can provision an Application Load Balancer (ALB) for HTTP application routing. The choice depends on protocol, routing needs, target type, workload placement, and whether the load balancer should be internal or internet-facing.

Option Typical role Targets and placement notes
Network Load Balancer (NLB) Layer 4 TCP or UDP traffic, commonly provisioned by a Service of type LoadBalancer With the VPC CNI, the AWS Load Balancer Controller supports EC2 IP or instance targets and Fargate IP targets. For IPv6 Pods, AWS supports load balancing with IP targets rather than instance targets.
Application Load Balancer (ALB) Layer 7 HTTP application routing, commonly provisioned through an Ingress Choose this when HTTP application routing is required; confirm target and workload compatibility for the cluster’s CNI configuration.

Target support can differ with alternate CNI configurations, so do not assume that an option documented for the VPC CNI applies unchanged elsewhere. AWS recommends the AWS Load Balancer Controller for new NLBs. Replacing existing controller-managed load balancers can create multiple NLBs and may cause downtime, so plan a migration rather than assuming a controller change is transparent.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

A practical order for networking decisions

  1. Choose the address family at cluster creation. Decide between IPv4 and IPv6 after checking node, workload, and service compatibility; changing the family later requires a new cluster and workload migration.
  2. Size the VPC and subnets. Meet the two-subnet, two-Availability-Zone cluster requirement and reserve sufficient addresses for nodes, Pods, and other resources.
  3. Define endpoint reachability. Select public, private, or both API endpoint access based on where operators and automation run, then align private DNS association and cluster security-group rules.
  4. Select traffic segmentation and AWS access controls. Decide where namespace-scoped NetworkPolicy is needed and where Pod-level AWS security-group controls are appropriate; verify support against the actual add-on version and node type.
  5. Choose application exposure. Use an NLB for Layer 4 TCP/UDP traffic or an ALB/Ingress for Layer 7 HTTP routing, and confirm target mode, workload placement, and internal versus internet-facing exposure.
  6. Assign ownership for networking capabilities. Account for whether the cluster uses EKS Auto Mode capabilities or separately managed add-ons, and document the configuration that the platform team must maintain.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.