Amazon EKS
User Guide

Amazon EKS IAM Policies, Roles, and Permissions

By default, IAM users don't have permission to create or modify Amazon EKS resources, or perform tasks using the Amazon EKS API. (This means that they also can't do so using the Amazon EKS console or the AWS CLI.) To allow IAM users to create or modify clusters, you must create IAM policies that grant IAM users permissions to use the specific resources and API actions that they need, and then attach those policies to the IAM users or groups that require those permissions.

When you attach a policy to a user or group of users, it allows or denies the users permission to perform the specified tasks on the specified resources. For more information, see Permissions and Policies in the IAM User Guide. For more information about managing and creating custom IAM policies, see Managing IAM Policies.

Likewise, Amazon EKS makes calls to other AWS services on your behalf, so the service must authenticate with your credentials. This authentication is accomplished by creating an IAM role and policy that can provide these permissions and then associating that role with your compute environments when you create them. For more information, see Amazon EKS Service IAM Role and also IAM Roles in the IAM User Guide.

Getting Started

An IAM policy must grant or deny permissions to use one or more Amazon EKS actions.