EKS Cluster with Managed Node Groups
Opinionated EKS cluster with node groups, core add-ons, Pod Identity, and KMS secret encryption.
Compare Managed Kubernetes across clouds →
Part of: AWS Container Platform (EKS)
Verification
Live-testedReally deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan test superseded by live test
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-06-29 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o aws-eks-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/aws-eks/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle aws-eks-1.0.0.sigstore.json \
aws-eks-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "e1cdbbc17cdfafaba4928ef2d29ee590359b3687f3b5d390832f1c8e20dea334 aws-eks-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "eks" {
source = "www.iac-bazaar.com/iac-bazaar/aws-eks/aws"
version = "1.0.0"
}Paid module — needs a purchase (or a subscription that covers it) plus a registry token from /account/tokens. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every Free module. This one is Premium, so its contract unlocks when you buy it.
Documentation
aws-eks
Opinionated EKS cluster with managed node groups, core add-ons, EKS Pod
Identity, and KMS secret encryption. Works with Terraform and OpenTofu
(>= 1.6), AWS provider >= 6.0, < 7.0.
Secure defaults:
- KMS envelope encryption of Kubernetes secrets (dedicated rotation-enabled key created unless you bring your own)
- Private API endpoint always enabled; public endpoint CIDR-restrictable or off
- Control-plane logging (
api,audit,authenticator) to a retention-managed CloudWatch log group - Modern
APIauthentication mode (access entries) andSTANDARDupgrade policy (no surprise extended-support billing) - No SSH/remote access to nodes; least-privilege cluster and node IAM roles
- Default add-on set includes
eks-pod-identity-agent, so Pod Identity associations work out of the box
Requirements
- Terraform or OpenTofu
>= 1.6 - AWS provider
>= 6.0, < 7.0 - An existing VPC with private subnets in at least two AZs (pair with the
aws-vpcmodule)
License
Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).
Usage code & full reference unlock after purchase
The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.
- Usage
- Inputs
- Outputs
- Notes
Related modules
Alibaba Cloud ACK Cluster
Managed ACK Kubernetes with node pools, VPC integration, and RAM roles.
Azure Kubernetes Service Cluster
Hardened AKS with system/user node pools, workload identity, Entra RBAC integration, Azure CNI overlay, and Container Insights wired in.
Civo Kubernetes Cluster
Fast-launch k3s cluster with node pools, firewall rules, and network.
DigitalOcean DOKS Cluster
Production DOKS with node pools, VPC, registry hookup, and maintenance windows in one apply.
Exoscale SKS Cluster
SKS Kubernetes with node pools, security groups, and anti-affinity.
GKE Cluster (Autopilot & Standard)
Private, Workload-Identity-enabled GKE cluster with managed node pools, release channels and maintenance windows, hardened to Google best practice.