Prerequisites for Amazon EKS cluster support
This section includes the prerequisites for monitoring runtime behavior of your Amazon EKS resources. These prerequisites are crucial for the GuardDuty agent to function as expected. After these prerequisites are met, see Enabling GuardDuty Runtime Monitoring to start monitoring your resources.
Support for Amazon EKS features
Runtime Monitoring supports Amazon EKS clusters running on Amazon EC2 instances and Amazon EKS Auto Mode.
Runtime Monitoring doesn't support Amazon EKS clusters with Amazon EKS Hybrid Nodes, and those running on AWS Fargate.
For information about these Amazon EKS features, see What is Amazon EKS? in the Amazon EKS User Guide.
Validating architectural requirements
The platform that you use may impact how GuardDuty security agent supports GuardDuty in receiving the runtime events from your EKS clusters. You must validate that you're using one of the verified platforms. If you're managing the GuardDuty agent manually, ensure that the Kubernetes version supports the GuardDuty agent version that is currently in use.
Verified platforms
For the verified CPU architectures, OS distributions, and kernel versions, see Supported CPU architectures, operating systems, and kernel versions.
Presently, with kernel version 5.4 in ARM64(aarch64), GuardDuty can't generate GuardDuty Runtime Monitoring finding types that are
related to Domain Name System (DNS) events.
Kubernetes versions supported by GuardDuty security agent
The following table shows the Kubernetes versions for your EKS clusters that are supported by GuardDuty security agent.
| Amazon EKS add-on GuardDuty security agent version | Kubernetes version |
|---|---|
|
v1.17.1 (latest - v1.17.1-eksbuild.2) |
1.31 - 1.36 |
|
v1.16.0 (latest - v1.16.0-eksbuild.2) |
1.28 - 1.36 |
|
v1.15.0 (latest - v1.15.0-eksbuild.2) |
1.28 - 1.36 |
|
v1.12.2 (latest - v1.12.2-eksbuild.2) |
1.28 - 1.36 |
|
v1.12.1 (latest - v1.12.1-eksbuild.4) |
1.28 - 1.35 |
|
v1.11.0 (latest - v1.11.0-eksbuild.4) |
1.28 - 1.34 |
|
v1.10.0 (latest - v1.10.0-eksbuild.2) |
1.21 - 1.33 |
|
v1.9.0 (latest - v1.9.0-eksbuild.2) v1.8.1 (latest - v1.8.1-eksbuild.2) |
1.21 - 1.32 |
|
v1.7.1 v1.7.0 v1.6.1 |
1.21 - 1.31 |
|
v1.6.0 v1.5.0 v1.4.1 v1.4.0 v1.3.1 |
1.21 - 1.29 |
|
v1.3.0 v1.2.0 |
1.21 - 1.28 |
|
v1.1.0 |
1.21 - 1.26 |
|
v1.0.0 |
1.21 - 1.25 |
Some of the GuardDuty security agent versions will reach end of standard support.
For information about the agent release versions, see GuardDuty security agent versions for Amazon EKS resources.
CPU and memory limits
The following table shows the CPU and memory limits for the Amazon EKS add-on for GuardDuty
(aws-guardduty-agent).
| Parameter | Minimum limit | Maximum limit |
|---|---|---|
CPU |
200m |
1000m |
Memory |
256 Mi |
1024 Mi |
When you use Amazon EKS add-on version 1.5.0 or above, GuardDuty provides the capability to configure the add-on schema for your CPU and memory values. For information about the configurable range, see Configurable parameters and values.
After you enable EKS Runtime Monitoring and assess the coverage status of your EKS clusters, you can set up and view the container insight metrics. For more information, see Setting up CPU and memory monitoring.
Validating your organization service control policy
If you have set up a service control policy (SCP) to manage permissions in your
organization, validate that permissions boundary is not restricting
guardduty:SendSecurityTelemetry. GuardDuty requires this permission to support Runtime Monitoring
across different resource types.
If your account is a member account, contact the associated delegated administrator. For information about managing SCPs for your organization, see Service control policies (SCPs).