EKS cluster API server endpoint is publicly accessible without private endpoint

Severity
High
Service
EKS
Check ID
EKS_PUBLIC_ENDPOINT

What this check finds

When the EKS API server is public-only, the Kubernetes control plane is reachable from the internet. Combined with any credential leak, this can allow cluster takeover. Enabling the private endpoint while disabling or restricting the public endpoint eliminates this exposure.

Passing looks like: EKS API endpoint not publicly accessible.

How to fix it

Enable the private endpoint and restrict (or disable) the public endpoint.

AWS CLI

  1. aws eks update-cluster-config --name CLUSTER_NAME --resources-vpc-config endpointPublicAccess=false,endpointPrivateAccess=true

Names in capitals are placeholders for your own resource. Review a command before you run it.

AWS console

EKS → Clusters → select cluster → Networking → Manage networking → set Private access On, Public access Off or restrict to known CIDRs.

Compliance controls it is evidence for

A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works

Compliance controls mapped to EKS cluster API server endpoint is publicly accessible without private endpoint
FrameworkControls
PCI-DSS v4.0.1
  • 1.3 Network access to and from the cardholder data environment is restricted
HIPAA Security Rule
  • 164.312(e)(2) Network segmentation — protect ePHI network segments
SOC 2 — Trust Services Criteria
  • CC6.4 Network Security Controls
NIST SP 800-53 Rev5 (Moderate)
  • SC-7 Boundary Protection
NIST Cybersecurity Framework 2.0
  • PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
ISO/IEC 27001:2022 Annex A
  • A.8.20 Networks security

Checked on every scan

KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs

Find out what is actually exposed in your AWS environment.

Connect one AWS account and run your first security assessment.

No credit card · Agentless · Read-only