Runbook 02 — Enterprise EKS Review
Runbook Information
Section titled “Runbook Information”| Item | Details |
|---|---|
| Runbook ID | AWS-EKS-RB-02 |
| Type | Enterprise Architecture & Security Review |
| Difficulty | Expert |
| Estimated Time | 1–2 Business Days |
| Platform | Amazon EKS |
| Cloud Provider | AWS |
| Primary Role | Principal Cloud Security Engineer |
| Supporting Roles | Cloud Architect, Kubernetes Administrator, DevOps Engineer, DevSecOps Engineer, SOC Analyst, Platform Engineering |
| Review Type | Production Readiness Review |
| Frequency | Quarterly or Before Production Go-Live |
| Classification | Internal Use Only |
Executive Summary
Section titled “Executive Summary”This runbook provides a structured methodology for performing a complete enterprise review of an Amazon EKS platform.
Unlike a technical security assessment that focuses on individual controls, this review evaluates the entire Kubernetes platform from an enterprise perspective, including:
- Architecture
- Governance
- Operational maturity
- Identity
- Networking
- Infrastructure
- Workloads
- Security
- Compliance
- Monitoring
- Business continuity
- Disaster recovery
- Operational excellence
The review determines whether the Amazon EKS platform is suitable for production deployment while aligning with organisational security standards and AWS best practices.
Enterprise Scenario
Section titled “Enterprise Scenario”CloudNova Technologies has completed the migration of several enterprise applications to Amazon EKS.
Before onboarding customer-facing production workloads, the Executive Technology Review Board has requested a formal Enterprise EKS Review.
The review must determine whether the platform is:
- Secure
- Scalable
- Highly available
- Governed
- Recoverable
- Observable
- Operationally mature
The outcome will determine whether production deployment is approved.
Review Objectives
Section titled “Review Objectives”Validate the enterprise readiness of:
- Platform Architecture
- AWS Account Design
- Networking
- Identity
- Kubernetes Configuration
- Cluster Operations
- Worker Nodes
- Application Security
- Secrets Management
- Observability
- Incident Response
- Compliance
- Governance
- Business Continuity
- Disaster Recovery
Enterprise Review Architecture
Section titled “Enterprise Review Architecture” AWS Organization
│
▼
AWS Landing Zone
│
▼
Production AWS Account
│
▼
Amazon VPC
│
┌────────────────────────────────────┐
│ Amazon EKS Platform │
│ │ │ Control Plane │ │ Worker Nodes │ │ Kubernetes │ │ Networking │ │ Storage │ │ Security │ │ Monitoring │ │ Governance │
└────────────────────────────────────┘
│ │
▼ ▼
AWS Native Services Enterprise SOC
│ │
▼ ▼
Compliance Executive ReportingEnterprise Review Workflow
Section titled “Enterprise Review Workflow”Preparation
│
▼
Architecture Review
│
▼
Infrastructure Review
│
▼
Identity Review
│
▼
Networking Review
│
▼
Workload Review
│
▼
Operations Review
│
▼
Governance Review
│
▼
Compliance Review
│
▼
Risk Assessment
│
▼
Executive DecisionReview Scope
Section titled “Review Scope”Architecture
Section titled “Architecture”Review:
- Multi-AZ design
- VPC architecture
- High availability
- Scalability
- Fault tolerance
- Landing Zone alignment
AWS Infrastructure
Section titled “AWS Infrastructure”Review:
- AWS Accounts
- IAM
- Organizations
- SCPs
- Route53
- Load Balancers
- Auto Scaling
- VPC Endpoints
- Transit Gateway
Amazon EKS Platform
Section titled “Amazon EKS Platform”Review:
- Kubernetes version
- Control Plane
- Managed Node Groups
- Cluster Autoscaler
- Add-ons
- CNI
- CSI Drivers
- Upgrade process
Identity
Section titled “Identity”Validate:
- IAM
- IRSA
- RBAC
- Service Accounts
- Federation
- MFA
- Least Privilege
Networking
Section titled “Networking”Review:
- VPC
- Subnets
- NAT Gateway
- Internet Gateway
- Route Tables
- Security Groups
- Network ACLs
- NetworkPolicies
- DNS
- Ingress
- Egress
Workloads
Section titled “Workloads”Review:
- Security Contexts
- Pod Security Admission
- Resource Limits
- Readiness Probes
- Liveness Probes
- Health Checks
- Deployments
- StatefulSets
- DaemonSets
- CronJobs
Container Security
Section titled “Container Security”Review:
- Approved Registries
- Image Signing
- Image Scanning
- Immutable Tags
- Base Images
- Supply Chain
Secrets Management
Section titled “Secrets Management”Review:
- AWS Secrets Manager
- KMS
- IRSA
- External Secrets Operator
- Secret Rotation
- Secret Ownership
Observability
Section titled “Observability”Validate:
- CloudWatch
- Container Insights
- Prometheus
- Grafana
- Fluent Bit
- CloudTrail
- GuardDuty
- Security Hub
Incident Response
Section titled “Incident Response”Review:
- Logging
- Alerting
- Runbooks
- Evidence Collection
- Isolation Procedures
- Recovery Procedures
Backup & Disaster Recovery
Section titled “Backup & Disaster Recovery”Review:
- Velero
- EBS Snapshots
- Persistent Volumes
- etcd Protection
- Restore Procedures
- Cross-Region Recovery
- RTO
- RPO
Governance
Section titled “Governance”Review:
- Naming Standards
- Labels
- Tags
- Ownership
- Policies
- Change Control
- Documentation
- Operational Standards
Compliance
Section titled “Compliance”Validate alignment with:
- AWS Well-Architected Framework
- CIS Kubernetes Benchmark
- CIS AWS Foundations Benchmark
- NIST SP 800-53
- ISO 27001
- PCI DSS (where applicable)
- SOC 2
- Internal Security Standards
Enterprise Review Phases
Section titled “Enterprise Review Phases”Phase 1 — Architecture Review
Section titled “Phase 1 — Architecture Review”Validate:
- Multi-AZ deployment
- Fault tolerance
- High availability
- Scalability
- Regional design
- Future expansion
Phase 2 — Infrastructure Review
Section titled “Phase 2 — Infrastructure Review”Assess:
- VPC
- IAM
- Security Groups
- KMS
- DNS
- Load Balancers
- Storage
Phase 3 — Kubernetes Review
Section titled “Phase 3 — Kubernetes Review”Review:
- Cluster health
- Node health
- Add-ons
- Networking
- Storage
- Scheduling
- Resource management
Phase 4 — Security Review
Section titled “Phase 4 — Security Review”Assess:
- IAM
- IRSA
- RBAC
- Secrets
- Runtime Security
- Supply Chain
- Encryption
- Monitoring
Phase 5 — Operational Review
Section titled “Phase 5 — Operational Review”Evaluate:
- Monitoring
- Alerting
- Upgrades
- Incident response
- Maintenance
- Capacity planning
Phase 6 — Governance Review
Section titled “Phase 6 — Governance Review”Review:
- Documentation
- Ownership
- Standards
- Processes
- Reviews
- Audits
Enterprise Assessment Checklist
Section titled “Enterprise Assessment Checklist”| Domain | Status |
|---|---|
| Architecture Reviewed | ☐ |
| AWS Infrastructure Reviewed | ☐ |
| EKS Configuration Reviewed | ☐ |
| Networking Reviewed | ☐ |
| IAM Reviewed | ☐ |
| IRSA Validated | ☐ |
| RBAC Reviewed | ☐ |
| Worker Nodes Reviewed | ☐ |
| Workloads Reviewed | ☐ |
| Secrets Reviewed | ☐ |
| Image Security Reviewed | ☐ |
| Logging Reviewed | ☐ |
| Monitoring Reviewed | ☐ |
| GuardDuty Reviewed | ☐ |
| Security Hub Reviewed | ☐ |
| Backup Strategy Reviewed | ☐ |
| Disaster Recovery Reviewed | ☐ |
| Compliance Reviewed | ☐ |
| Governance Reviewed | ☐ |
| Risks Documented | ☐ |
| Executive Report Completed | ☐ |
Enterprise Risk Classification
Section titled “Enterprise Risk Classification”Critical
Section titled “Critical”Examples:
- Single Availability Zone deployment
- No disaster recovery strategy
- Administrator IAM permissions
- Public Kubernetes API without restrictions
- No audit logging
- No secrets management
- Unsupported Kubernetes version
Examples:
- Missing NetworkPolicies
- Weak RBAC
- No runtime monitoring
- Missing backup validation
- Unencrypted storage
- Missing IRSA
Medium
Section titled “Medium”Examples:
- Incomplete documentation
- Missing labels
- Weak naming standards
- Manual operational procedures
Examples:
- Documentation improvements
- Tagging consistency
- Minor governance issues
Production Readiness Scorecard
Section titled “Production Readiness Scorecard”| Domain | Score |
|---|---|
| Architecture | /10 |
| AWS Infrastructure | /10 |
| Amazon EKS Platform | /10 |
| Identity & Access | /10 |
| Networking | /10 |
| Security Controls | /10 |
| Secrets Management | /10 |
| Observability | /10 |
| Operations | /10 |
| Governance & Compliance | /10 |
Overall Enterprise Score: ____ /100
Production Readiness Rating
Section titled “Production Readiness Rating”| Score | Rating |
|---|---|
| 95–100 | Production Ready |
| 85–94 | Production Ready with Minor Improvements |
| 70–84 | Conditionally Ready |
| 50–69 | Significant Remediation Required |
| Below 50 | Not Approved for Production |
Findings Register
Section titled “Findings Register”| Finding ID | Finding | Severity | Domain | Owner | Status |
|---|---|---|---|---|---|
| EKS-ENT-001 | Open |
Risk Register
Section titled “Risk Register”| Risk ID | Risk | Severity | Likelihood | Impact | Treatment |
|---|---|---|---|---|---|
| EKS-RISK-001 | Public API Endpoint Exposure | Critical | Medium | High | Immediate Remediation |
| EKS-RISK-002 | Excessive IAM Permissions | High | Medium | High | Least Privilege Implementation |
| EKS-RISK-003 | Missing Disaster Recovery Testing | High | Medium | High | Conduct DR Exercises |
| EKS-RISK-004 | Weak Governance Controls | Medium | Medium | Medium | Improve Operational Processes |
Executive Recommendations
Section titled “Executive Recommendations”Immediate (0–30 Days)
Section titled “Immediate (0–30 Days)”- Remove critical security findings.
- Eliminate excessive IAM permissions.
- Restrict Kubernetes API access.
- Enable all required audit logging.
- Implement missing NetworkPolicies.
- Validate backup and restore procedures.
Short-Term (30–60 Days)
Section titled “Short-Term (30–60 Days)”- Standardise cluster governance.
- Improve monitoring coverage.
- Complete workload hardening.
- Enhance incident response procedures.
- Validate disaster recovery processes.
Long-Term (60–180 Days)
Section titled “Long-Term (60–180 Days)”- Implement continuous compliance monitoring.
- Automate security assessments.
- Improve platform resilience.
- Expand Zero Trust networking.
- Mature operational governance.
Best Practices
Section titled “Best Practices”- Use managed EKS add-ons where practical.
- Keep Kubernetes versions supported and current.
- Apply least-privilege IAM and Kubernetes RBAC.
- Isolate workloads with namespaces and NetworkPolicies.
- Use IRSA for workload identity.
- Store secrets in AWS Secrets Manager with KMS encryption.
- Enable comprehensive logging and monitoring.
- Test backup and disaster recovery procedures regularly.
- Conduct quarterly enterprise platform reviews.
- Integrate security assessments into CI/CD and operational workflows.
Knowledge Check
Section titled “Knowledge Check”Question 1
Section titled “Question 1”Why is an Enterprise EKS Review different from a standard security assessment?
Answer: It evaluates not only security controls but also architecture, operational maturity, governance, resilience, compliance, and production readiness across the entire Kubernetes platform.
Question 2
Section titled “Question 2”Why should disaster recovery be included in an EKS review?
Answer: A secure platform must also be recoverable. Backup validation, restore testing, and defined RTO/RPO objectives are essential for business continuity.
Question 3
Section titled “Question 3”What is the benefit of a production readiness scorecard?
Answer: It provides stakeholders with a measurable view of platform maturity, identifies priority improvements, and supports informed go-live decisions.
Question 4
Section titled “Question 4”Why should governance be reviewed alongside technical controls?
Answer: Strong governance ensures consistent standards, ownership, change control, documentation, and long-term operational sustainability.
Question 5
Section titled “Question 5”How often should an Enterprise EKS Review be performed?
Answer: At least quarterly, before major production releases, after significant architectural changes, and following major security incidents.
Runbook Summary
Section titled “Runbook Summary”This runbook provides a comprehensive framework for evaluating Amazon EKS from an enterprise perspective.
The review extends beyond technical validation by assessing:
- Platform architecture
- AWS infrastructure
- Kubernetes operations
- Identity and access management
- Network security
- Workload security
- Secrets management
- Observability
- Incident response
- Backup and disaster recovery
- Governance
- Compliance
- Production readiness
The final deliverable enables leadership teams to determine whether the Amazon EKS platform is operationally mature, secure, resilient, and ready to host critical production workloads while supporting long-term enterprise operations.
What’s Next?
Section titled “What’s Next?”Next Runbook: Runbook 03 — Amazon EKS Incident Response & Security Investigation
In the next runbook, you will investigate Amazon EKS security incidents by collecting forensic evidence, analyzing Kubernetes audit logs, CloudTrail events, GuardDuty findings, workload activity, IAM changes, network traffic, and runtime alerts to determine root cause, assess impact, and coordinate containment, eradication, and recovery.