Amazon EKS in Production
Run Kubernetes in production on AWS. Provision, secure, network, scale, observe, and upgrade Amazon EKS clusters with managed node groups, Fargate, and Karpenter, plus a tour of EKS Auto Mode. For engineers who already know Kubernetes and want the AWS-specific layer.
Course Preview
Why This Course is Different
Get everything you need to master platform engineering and advance your career
Certificate of Completion
Earn a certificate while gaining real-world skills that go beyond traditional certification prep
Hands-on Labs
8 practical labs with real-world scenarios in pre-configured cloud environments
Expert-Led
Learn from Sam Gabrail, Former HashiCorp Sr. Solutions Engineer with 18+ years experience
Community Support
Join our community where members help each other and collaborate on learning
What You'll Master
Explain what Amazon EKS manages and what stays your responsibility
Provision EKS clusters with eksctl and Terraform and configure access entries
Reason about VPC CNI IP allocation, prefix delegation, and security groups for pods
Choose between managed node groups, Fargate, Karpenter, and EKS Auto Mode
Scale workloads and nodes with metrics-server, HPA, Cluster Autoscaler, and Karpenter
Grant pods AWS access with IRSA and EKS Pod Identity using least privilege
Provision storage with the EBS, EFS, and S3 CSI drivers and inject secrets with the Secrets Store CSI Driver
Expose workloads with the AWS Load Balancer Controller, ACM, and ExternalDNS
Manage EKS add-ons, observability, and the cluster upgrade lifecycle
Apply AWS-native security and cost-optimization practices to an EKS cluster
Design multi-AZ, multi-tenant, GitOps-driven production EKS architectures
Course Curriculum
SECTION 1 β EKS FOUNDATIONS & KUBERNETES REFRESHER
What Amazon EKS is and is not, a fast Kubernetes refresher for EKS, the managed control-plane and data-plane architecture, and EKS pricing and the Kubernetes version lifecycle.
- β’What Amazon EKS Is and Isn't
- β’A Fast Kubernetes Refresher for EKS
- β’EKS Architecture: Control Plane, Data Plane & Endpoints
- β’EKS Pricing & the Kubernetes Version Lifecycle
- β’Section 1 Quiz: EKS FoundationsQuiz
SECTION 2 β PROVISIONING EKS CLUSTERS
Provisioning options compared (console, eksctl, Terraform, CloudFormation, CDK), cluster IAM and VPC requirements, public versus private endpoints, and cluster access management with access entries versus the legacy aws-auth ConfigMap.
- β’Provisioning Options Compared: Console, eksctl, Terraform, CloudFormation, CDK
- β’Cluster IAM Role, VPC and Subnet Requirements, and API Endpoint Access
- β’Creating a Cluster with eksctl
- β’Creating a Cluster with the terraform-aws-modules/eks Module
- β’Cluster Access Management: Access Entries vs the Legacy aws-auth ConfigMap
- β’Section 2 Quiz: Provisioning EKS ClustersQuiz
- β’Provision Your First EKS ClusterLab
SECTION 3 β NETWORKING ON EKS
The Amazon VPC CNI and how pod IPs come from the VPC, IP exhaustion and prefix delegation, security groups for pods, the VPC CNI network-policy engine, and alternative CNIs and IPv6 clusters.
- β’The Amazon VPC CNI: Pod IPs Come From the VPC
- β’IP Exhaustion and Prefix Delegation
- β’Security Groups for Pods
- β’The VPC CNI Network-Policy Engine
- β’Alternative CNIs and IPv6 Clusters
- β’Section 3 Quiz: Networking on EKSQuiz
- β’VPC CNI Deep-Dive: IP Allocation & Security Groups for PodsLab
SECTION 4 β COMPUTE & AUTOSCALING
Managed node groups, self-managed nodes, Fargate profiles, pod autoscaling with metrics-server and HPA, node autoscaling with Cluster Autoscaler and Karpenter, EKS Auto Mode, and choosing a compute model.
- β’Managed Node Groups
- β’Self-Managed Nodes and Launch Templates
- β’AWS Fargate Profiles
- β’Pod Autoscaling: metrics-server and the HPA
- β’Node Autoscaling I: Cluster Autoscaler
- β’Node Autoscaling II: Karpenter
- β’EKS Auto Mode: Managed Compute End to End
- β’Choosing a Compute Model
- β’Section 4 Quiz: Compute & AutoscalingQuiz
- β’Autoscaling: metrics-server, HPA & KarpenterLab
SECTION 5 β IDENTITY & ACCESS
The IAM to Kubernetes RBAC bridge, IAM Roles for Service Accounts (IRSA), EKS Pod Identity and cross-account target-role chaining, and an IRSA versus Pod Identity decision matrix with least-privilege patterns.
- β’The IAM to Kubernetes RBAC Bridge
- β’IAM Roles for Service Accounts (IRSA)
- β’EKS Pod Identity
- β’IRSA vs Pod Identity: Decision Matrix and Least Privilege
- β’Section 5 Quiz: Identity & AccessQuiz
- β’Grant a Pod AWS Access with EKS Pod IdentityLab
SECTION 6 β STORAGE & SECRETS INJECTION
The EBS and EFS CSI drivers, Mountpoint for Amazon S3, the Secrets Store CSI Driver with the AWS Secrets and Config Provider (ASCP), and snapshots, volume expansion, and data lifecycle on EKS.
- β’The EBS CSI Driver and StorageClasses
- β’The EFS CSI Driver for Shared RWX Storage
- β’Mountpoint for Amazon S3 CSI Driver
- β’Mounting AWS Secrets with the Secrets Store CSI Driver and ASCP
- β’Snapshots, Volume Expansion, and Data Lifecycle
- β’Section 6 Quiz: Storage & Secrets InjectionQuiz
- β’EBS CSI Dynamic ProvisioningLab
SECTION 7 β LOAD BALANCING & INGRESS
The in-tree LoadBalancer Service versus the AWS Load Balancer Controller, installing and configuring the controller, ALB Ingress patterns, NLB for L4 with ACM TLS termination, and ExternalDNS with Route 53.
- β’In-Tree LoadBalancer Service vs the AWS Load Balancer Controller
- β’Installing and Configuring the AWS Load Balancer Controller
- β’ALB Ingress Patterns: Path and Host Routing, Target Types, and IngressGroups
- β’NLB for Layer 4 and TLS Termination with ACM
- β’ExternalDNS and Route 53 Integration
- β’Section 7 Quiz: Load Balancing & IngressQuiz
- β’Expose a Workload with the AWS Load Balancer ControllerLab
SECTION 8 β ADD-ONS, OBSERVABILITY, UPGRADES & TROUBLESHOOTING
EKS managed add-ons, control-plane logging to CloudWatch, Container Insights, Amazon Managed Service for Prometheus with Grafana, upgrading EKS, and troubleshooting common EKS failure modes.
- β’EKS Managed Add-ons
- β’Control-Plane Logging to CloudWatch
- β’CloudWatch Container Insights
- β’Amazon Managed Prometheus and Grafana
- β’Upgrading EKS and the Version Treadmill
- β’Troubleshooting EKS Failure Modes
- β’Section 8 Quiz: Add-ons, Observability, Upgrades & TroubleshootingQuiz
- β’Day-2 Ops: Logging, Upgrade & Container InsightsLab
SECTION 9 β SECURITY & COST OPTIMIZATION
Secrets envelope encryption with KMS and the EKS-default Pod Security Admission behavior, image security with Amazon ECR, GuardDuty EKS Protection, and EKS cost optimization including Spot, right-sizing, and the extended-support cost trap.
- β’Envelope Encryption with KMS & the EKS Pod Security Admission Default
- β’Image Security with Amazon ECR
- β’GuardDuty EKS Protection & Runtime Monitoring
- β’EKS Cost Optimization
- β’Section 9 Quiz: Security & Cost OptimizationQuiz
SECTION 10 β PRODUCTION PATTERNS & CAPSTONE
Multi-AZ high availability and resilience, multi-tenancy on EKS, GitOps with ArgoCD, backup and disaster recovery with Velero, and a capstone walkthrough of a production multi-tier application.
- β’Multi-AZ High Availability on EKS
- β’Multi-Tenancy on EKS
- β’GitOps on EKS with ArgoCD
- β’Backup and DR: Velero, Snapshots, and Upgrade Strategies
- β’Capstone Walkthrough and Where to Go Next
- β’Section 10 Quiz: Production Patterns & CapstoneQuiz
- β’Capstone: Deploy a Multi-Tier App End-to-EndLab
Course Features

Hands-on Labs
Lots of hands-on labs to learn by doing

Join our Community
Community support to ask questions and collaborate

Test Your Knowledge
Quizzes to help you grasp the material well
See what others are saying about our Courses
βI like the Crossplane 101 course a lot. I think it is one of the best online courses I have taken (and I've taken a lot in the last 2 years, transitioning into DevOps). The labs are phenomenal β every task has a long tutorial with lots of explanations, gotchas, and recaps, and you always provide the reasoning for implementing a certain solution.β
βI just completed the Crossplane 101 course! Managing infrastructure as Kubernetes resources is a total game-changer. A huge thanks to TeKanAid and Sam Gabrail for the incredible training and insights.β
βAlthough I've worked with Crossplane in real production environments, I always felt there were gaps in my understanding. Completing this course filled those gaps perfectly. I had to unlearn and relearn quite a few things, especially around Crossplane v2.0 concepts. Well structured and thoughtfully put together. Highly recommended for building a strong, foundational understanding of Crossplane.β
βDear Sam, I hope this email finds you well. If you remember before the end of last year I register for one your courses Terraform 101 β Certified Terraform Associate, I must admit that I learned a lot even though I was not patient enough for all videos to be available. All in all I enjoy the way you structured the course and how you went through it. The main reason of this email, to send you my gratitude for the content you created and to let you know that I passed my exam/test last week.β

βThis course was a perfect introduction to Terraform and Infrastructure as Code. Loved the gitpod, saving me a lot of time for developer environment setup. We have a project at work where we want to go from a click-ops version of server-deploy to a more automated flow using ci/cd and terraform for deploying virtual servers.β

βI want to thank you for such wonderful courses. They are more comprehensive than other courses I have taken in the past. You take the time to explain every detail of the code and what it does exactly, further enforcing your student's understanding and confidence in what they are learning. Your methods are very effective and set you apart from other instructors.β

Choose your plan
Simple, Transparent Pricing
Unlock full access to TeKanAid courses, labs, and bootcamps
Just exploring? Start free below. Want the full experience? Try Premium free for 7 days (card required, $0 today).
Pro
All courses, with lab scripts to run on your own machine
Renews automatically. Cancel anytime.
Final price verified at checkout.
- Full access to all courses
- Lab scripts to download and run on your own machine (hosted labs not included)
- Progress tracking
- Certificate of completion
- Community access
- Bootcamp participation
- New content access
Premium
Full access, including unlimited hosted labs
Renews automatically. Cancel anytime.
Final price verified at checkout.
- Everything in Pro
- Unlimited hands-on labs, fully hosted on TeKanAid Academy (nothing to set up)
- Lab AI Assistant
- Accelerator bootcamps with live office hours
- Priority support
Prefer just this course?
Purchase Amazon EKS in Production for a one-time fee of $79. Full access to course content, quizzes, certificates, and community features, lab access is not included.
Buy this course for $79 βJust exploring? Start free, no account needed
Three free ways to start. All bridge into the paid Premium catalog when you're ready.
Not ready to commit? The crash course is email-only. No academy account required.
Hi there, I'm Sam
I'm a husband and father of two wonderful boys. I'm also very passionate π₯ about all things technology. From when I was 10, I had a dream to become a computer π» engineer one day. Here I am today living the dream!
Thanks for visiting TeKanAid Academy. My goal is to teach you all things DevOps. Below are some of the things I've done over the years. I'm confident that I can help you achieve your dreams too.
- 18+ years of experience in various Information Technology fields from Telecommunications, Computer Networks, Digital Transformation, DevOps, Cybersecurity, and IoT
- President of TeKanAid Solutions Inc. building online content in the DevOps space
- Previous β Sr. Solutions Engineer at HashiCorp

View my Certifications

Terraform: Authorized HashiCorp Instructor
Verify my certificate
HashiCorp Authorized Instructors are experienced DevOps professionals who deliver official HashiCorp training courses in person and virtually.
Issued by HashiCorp Partner Network (HPN)

Vault: Authorized HashiCorp Instructor
Verify my certificate
HashiCorp Authorized Instructors are experienced DevOps professionals who deliver official HashiCorp training courses in person and virtually.
Issued by HashiCorp Partner Network (HPN)

HashiCorp Certified: Terraform Associate (002)
Verify my certificate
Earners of the HashiCorp Certified: Terraform Associate certification know the basic concepts, skills, and use cases associated with open source HashiCorp Terraform.
Issued by HashiCorp

HashiCorp Certified: Vault Associate (002)
Verify my certificate
Earners of the HashiCorp Certified: Vault Associate certification know the basic concepts, skills, and use cases associated with open source HashiCorp Vault.
Issued by HashiCorp
Featured Products
Week 4: AI Agents and Agentic Workflows
Part of the AI Platform Engineering Bootcamp. Week 4 of 8. The bootcamp follows an 8-week arc that culminates in a capstone Platform Assistant: a production-ready AI system you build by combining the LLM, RAG, agent, MLOps, model serving, and observability layers introduced across each week.
Learn More βWeek 1: AI Foundations for Infrastructure Engineers
Part of the AI Platform Engineering Bootcamp. Week 1 of 8. The bootcamp follows an 8-week arc that culminates in a capstone Platform Assistant: a production-ready AI system you build by combining the LLM, RAG, agent, MLOps, model serving, and observability layers introduced across each week.
Learn More βWeek 7: AI Observability and LLMOps
Part of the AI Platform Engineering Bootcamp. Week 7 of 8. The bootcamp follows an 8-week arc that culminates in a capstone Platform Assistant: a production-ready AI system you build by combining the LLM, RAG, agent, MLOps, model serving, and observability layers introduced across each week.
Learn More β
30-Day Money-Back Guarantee
Try it risk-free
I'm confident you'll get everything you need from this course and be 100% satisfied. But in the unlikely event you decide it's not for you just ask for a refund any time during the first 30 days and you'll get your money back with no questions asked.