Containers

Category: Technical How-to

AI-powered EKS migration assessment with Amazon Bedrock AgentCore

AI-powered EKS migration assessment with Amazon Bedrock AgentCore

Learn how to build an AI-powered migration assessment agent using Amazon Bedrock AgentCore and the Strands Agents SDK. The agent reads application source code and container artifacts, scores Amazon EKS migration readiness, identifies blockers by severity, and generates an actionable migration plan with target architecture recommendations.

Fix pod distribution drift in Amazon EKS with the Kubernetes descheduler

Fix pod distribution drift in Amazon EKS with the Kubernetes descheduler

A workload spread across three Availability Zones does not necessarily stay spread. This post explains why soft topology spread constraints drift after a node-availability gap, measures the cost, and shows how the Kubernetes descheduler restores even pod distribution on Amazon EKS without downtime and without forcing hard constraints.

Building a single-pane NOC dashboard for Amazon EKS with Amazon CloudWatch

Building a single-pane NOC dashboard for Amazon EKS with Amazon CloudWatch

An incident is the worst moment to discover you cannot trust your Amazon EKS dashboard. This post shows what a trustworthy single-pane NOC for Amazon EKS on Amazon CloudWatch looks like, why each design choice matters, and how to get one running in your account in about 15 minutes.

Implement per-pod image pull permissions with ECR repository policies on Amazon EKS

Implement per-pod image pull permissions with ECR repository policies on Amazon EKS

Learn how to scope Amazon ECR image pull permissions to individual Kubernetes pods on a multi-tenant Amazon EKS cluster using KEP 4412 credential providers and ECR repository deny policies, so teams sharing the same nodes can pull only their own container images.

How Ramp runs GPU AI workloads at scale with ECS Managed Instances

How Ramp runs GPU AI workloads at scale with ECS Managed Instances

Ramp runs GPU-powered AI inference continuously on Amazon ECS. This post walks through how Ramp’s infrastructure team moved those GPU workloads onto Amazon ECS Managed Instances: the architecture pattern, Terraform implementation, and the lessons learned migrating 50 to 60 EC2 instances.

Break-glass access for Amazon EKS when federated identity fails

Break-glass access for Amazon EKS when federated identity fails

Implementing break-glass access for Amazon EKS clusters removes the circular dependency where a federated identity provider outage locks you out of the clusters you need to reach to fix it. This post supplies a cross-account IAM role with enforced MFA, infrastructure-as-code templates, validation tests, and a post-incident recovery procedure.

Deep dive into Amazon EKS certificate authority rotation

Deep dive into Amazon EKS certificate authority rotation

Amazon EKS now provides a managed, non-disruptive lifecycle for rotating your cluster’s certificate authority (CA), with automated safeguards and rollback. This deep dive explains how CA rotation works, what AWS handles versus what you must update, and how to walk through the rotation lifecycle on your own timeline.

Encrypt Amazon ECS traffic: VPC encryption controls and Service Connect TLS

Encrypt Amazon ECS traffic: VPC encryption controls and Service Connect TLS

Learn how to encrypt traffic between Amazon ECS workloads using two native approaches: VPC encryption controls for network-layer encryption through the AWS Nitro System, and Service Connect TLS for application-layer encryption. A hands-on walkthrough shows how to activate encryption on AWS Fargate and verify it in VPC Flow Logs.

Forensic container checkpointing on Amazon Elastic Kubernetes Service (Amazon EKS)

Forensic container checkpointing on Amazon Elastic Kubernetes Service (Amazon EKS)

Amazon EKS 1.34 makes the Kubelet Checkpoint API functional, so you can capture a running container’s full state (memory, processes, and network connections) without stopping the workload. This post shows how to deploy an unprivileged checkpoint agent that stores forensic checkpoints in Amazon ECR as OCI images for later analysis.