Official agent skill

Eks Best Practices

by aws-samples in aws-samples/appmod-blueprints

Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.

OfficialMIT-0Auto-check passedDevOps & Cloud

Install Eks Best Practices

skills CLI
$ npx skills add aws-samples/appmod-blueprints --skill eks-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws-samples/appmod-blueprints eks-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kiro/skills/eks-best-practices .claude/skills/eks-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
eks-best-practices
GitHub stars
113
Token cost
~5k tokens
SKILL.md length
1,770 words
Files
18 (incl. references)
Skills in repo
9
Repo updated
First seen
Licence
MIT-0

At a glance

Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.

  • Works in 6 steps: Check EKS Cluster Insights for upgrade… → Scan for deprecated APIs (Pluto,… → Verify add-on compatibility with target… → …
  • Any EKS planning
  • SKILL.md covers When to Use This Skill, EKS Architecture Decision…, Compute Selection Matrix and Networking Quick Reference, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Eks Best Practices is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning. Also answers Terraform configuration questions about terraform-aws-modules/terraform-aws-eks. Use for any EKS planning or architectural judgment call, even when phrased casually. Do NOT use for generating documents or code (eks-design, eks-build), scoring or auditing a live cluster (eks-operation-review…

Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including reference files (for example `references/argocd-patterns.md`, `references/autoscaling.md` and `references/cluster-upgrades.md`).

It sits in DevOps & Cloud, covering Infrastructure as code, Multi-tenancy and Platform engineering. It works with Amazon Web Services, Model Context Protocol, Terraform and vLLM. The licence is MIT-0.

When your agent uses it

  • Any EKS planning
  • Architectural judgment call
  • Even when phrased casually
  • Generating documents

Example prompts

  • “/eks-best-practices”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Check EKS Cluster Insights for upgrade readiness
  2. Scan for deprecated APIs (Pluto, kube-no-trouble)
  3. Verify add-on compatibility with target version
  4. Test in non-prod environment first
  5. Ensure PDBs are configured for graceful node drain
  6. Back up cluster state (Velero or GitOps repo)

What it can do on your machine

Read from SKILL.md and the folder at commit 42ea29c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • docs.aws.amazon.com
    • aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Eks Best Practices loads about 5k tokens when it runs, and up to ~85k if it reads all its reference files. Until then it costs about 234 tokens; SKILL.md has 1,770 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~234
When it runs · the whole SKILL.md, loaded when a task matches
~5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~85k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws-samples/appmod-blueprints at commit 42ea29c, republished under its MIT-0 licence (© aws-samples). 1,770 words, ~5,026 tokens.

Download SKILL.mdSave it as .claude/skills/eks-best-practices/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.
name
eks-best-practices
description
Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning. Also answers Terraform configuration questions about terraform-aws-modules/terraform-aws-eks. Use for any EKS planning or architectural judgment call, even when phrased casually. Do NOT use for generating documents or code (eks-design, eks-build), scoring or auditing a live cluster (eks-operation-review, eks-upgrade-check), discovering what is running (eks-recon), MCP tooling setup (eks-mcp-server), building developer platforms and IDPs (eks-platform-engineering), GenAI/LLM workload decisions — GPU vs Trainium/Inferentia, vLLM/Ray serving, distributed training, ML storage (eks-genai), or compliance-regime hardening and audit prep — HIPAA/PCI/FedRAMP, CIS benchmarks, GuardDuty, image signing (eks-security).

EKS Best Practices

Comprehensive guidance for designing, deploying, and operating Amazon EKS clusters. Consolidates guidance from the AWS EKS Best Practices Guide, AWS EKS HA/Resiliency Guide, and terraform-aws-modules/terraform-aws-eks examples.

When to Use This Skill

Activate this skill when:

  • Designing a new EKS cluster architecture
  • Choosing between EKS compute options (Fargate, MNG, Karpenter, Auto Mode)
  • Configuring EKS networking (VPC CNI, ingress, service mesh)
  • Implementing EKS security (IAM, pod security, secrets)
  • Planning cluster upgrades or migrations
  • Reviewing EKS architecture decisions
  • Working with terraform-aws-modules/terraform-aws-eks examples
  • Optimizing EKS cost or scaling to large clusters

Don't use this skill for:

  • Generic Kubernetes concepts (Claude knows these)
  • Provider-specific API reference (link to AWS docs)
  • Non-EKS container orchestration (ECS, Lambda)
  • Step-by-step EKS upgrade execution — this skill covers upgrade strategy and architectural decisions, not the per-version procedures themselves.

EKS Architecture Decision Framework

When to Use EKS
RequirementEKSECSLambda
Kubernetes ecosystem✅ Native K8s❌ AWS-proprietary❌
Portable across clouds✅ Standard K8s API❌ AWS-only❌ AWS-only
Long-running services✅✅⚠️ 15 min limit
Minimal ops overheadMediumLowLowest
GPU/ML workloads✅ Best supportLimited❌
Complex networking✅ Full controlMediumLimited
Team has K8s expertiseRequiredNot requiredNot required
EKS Deployment Models
ModelDescriptionOperational OverheadUse When
EKS StandardFull control over nodes, add-ons, networkingMedium-HighNeed full customization
EKS Auto ModeAWS manages nodes, add-ons, scalingLowWant minimal ops, standard workloads
EKS with FargateServerless pods, per-pod billingLowBatch, low-density workloads
EKS on OutpostsRun EKS on-premisesHighData residency, low-latency edge
EKS AnywhereEKS on your own infrastructureHighestAir-gapped, custom hardware
Shared Responsibility
ComponentAWS ManagesYou Manage
Control planeAPI server, etcd, HA, patchingRBAC, admission control, audit logging
Data plane (MNG)AMI updates, node healthInstance type, scaling, pod scheduling
Data plane (Fargate)EverythingPod spec, resource requests
Data plane (Auto Mode)Node lifecycle, OS patchingWorkload definitions
NetworkingENI attachment, VPC CNI releasesSubnet design, IP planning, ingress
SecurityControl plane authIAM, pod security, secrets, network policies

Compute Selection Matrix

Decision Table
FactorFargateMNGKarpenterAuto ModeSelf-Managed
Best forBatch, small scaleStable, predictableDynamic, variedMinimal opsCustom AMI/kernel
ScalingPer-podASG-basedFast, flexibleAWS-managedManual ASG
Spot support❌✅✅ Native✅✅
GPU support❌✅✅✅✅
DaemonSets❌✅✅✅✅
Cost modelPer vCPU/GB/hrPer EC2 instancePer EC2 instancePer EC2 instancePer EC2 instance
Max pods/node1ENI-basedENI-basedAWS-managedENI-based
Node SSH❌✅✅❌✅
OperationalLowestLowLowLowestHighest
Quick Decision Guide
  • Default choice: Karpenter — best balance of flexibility, cost, and automation
  • Zero ops priority: EKS Auto Mode — AWS manages nodes, add-ons, and scaling via managed Karpenter. Best for teams that want Kubernetes benefits without operational overhead around upgrades, autoscaling, load balancing, and storage
  • Serverless/batch: Fargate — no nodes to manage, per-pod billing
  • Predictable, stable: MNG — familiar ASG model, managed updates
  • Custom requirements: Self-managed — full control, highest overhead

✅ DO:

  • Use Karpenter as the default node autoscaler for new clusters
  • Run system components (CoreDNS, Karpenter) on MNG or Fargate
  • Use multiple instance types for availability and cost optimization

❌ DON'T:

  • Use self-managed nodes without a specific technical requirement
  • Run Fargate for GPU or DaemonSet-dependent workloads
  • Mix Karpenter and Cluster Autoscaler on the same node groups

Networking Quick Reference

VPC CNI Mode Decision
ModeUse WhenPod Density
Secondary IP (default)Most workloads, simple setupLimited by ENI × IPs per ENI
Prefix Delegation>30 pods/node, IP-constrained VPC4-16× more pods per node
Custom NetworkingPods need different CIDR than nodesSame as underlying mode
Ingress Pattern Selection
PatternBest ForKey Feature
ALB (via LBC)HTTP/HTTPS web appsNative WAF, Cognito auth
NLB (via LBC)TCP/UDP, gRPC, low latencyStatic IPs, source IP preservation
Gateway APIMulti-team, new deployments✅ Recommended standard
VPC LatticeCross-VPC service-to-serviceNo sidecar, IAM auth
IPv4 vs IPv6
FactorIPv4IPv6
Default choice✅ YesWhen facing IP exhaustion
AWS service supportFullMost (check specific services)
ComplexityStandardRequires dual-stack VPC

For detailed networking guidance, see: Networking — VPC CNI & IP | Networking — Ingress & DNS

Security Essentials

IAM Strategy
ApproachUse WhenSetup
Pod Identity✅ New workloads (EKS 1.24+)EKS add-on + association
IRSAOlder clusters, FargateOIDC provider + trust policy

Key rules:

  • ✅ Use Pod Identity for new workloads — simpler setup, session tags, role chaining
  • ✅ Use EKS access entries (API mode) over aws-auth ConfigMap
  • ✅ Move VPC CNI permissions from node role to Pod Identity/IRSA
  • ❌ Don't use wildcard conditions in IRSA trust policies
  • ❌ Don't attach application permissions to node IAM roles
Pod Security Baseline

Apply Pod Security Admission (PSA) labels to all namespaces:

yaml
# Minimum: enforce baseline, warn on restricted
metadata:
  labels:
    pod-security.kubernetes.io/enforce: baseline
    pod-security.kubernetes.io/warn: restricted
Secrets Management
ApproachComplexityBest For
External Secrets OperatorMedium✅ GitOps workflows
Secrets Store CSIMediumMount secrets as volumes
KMS envelope encryptionLowEncrypt etcd secrets

Always enable KMS envelope encryption for Kubernetes secrets.

For detailed security guidance, see: Security Reference | Runtime & Network | Supply Chain & Compliance

Reliability Essentials

Pod Disruption Budgets

Create PDBs for every production workload with >1 replica:

WorkloadRecommended PDB
Stateless (3+ replicas)minAvailable: "50%"
Stateful quorum (3)maxUnavailable: 1
Batch/jobmaxUnavailable: "50%"
SingletonNo PDB (would block all disruptions)
Health Probe Strategy
ProbePurposeKey Rule
StartupWait for slow initUse for apps >10s startup
ReadinessTraffic routing✅ Check dependencies here
LivenessDetect deadlocks❌ Never check dependencies

Critical rule: Liveness probes must NOT check external dependencies. If the database goes down and liveness checks the DB, ALL pods restart — causing cascading failure.

Graceful Shutdown Pattern
yaml
spec:
  terminationGracePeriodSeconds: 60
  containers:
  - lifecycle:
      preStop:
        exec:
          command: ["/bin/sh", "-c", "sleep 15"]

Why sleep 15: Gives kube-proxy and load balancer time to remove the pod from traffic routing before SIGTERM.

Multi-AZ Distribution
yaml
topologySpreadConstraints:
- maxSkew: 1
  topologyKey: topology.kubernetes.io/zone
  whenUnsatisfiable: DoNotSchedule

For detailed reliability guidance, see: Reliability & Resiliency — Core (see also reliability-advanced.md for DR, deployment strategies, and large-cluster guidance)

Cluster Upgrade Strategy

Upgrade Sequence (Strict Order)
1. Control Plane → 2. EKS Add-ons → 3. Data Plane → 4. Custom Add-ons
Pre-Upgrade Checklist
  1. Check EKS Cluster Insights for upgrade readiness
  2. Scan for deprecated APIs (Pluto, kube-no-trouble)
  3. Verify add-on compatibility with target version
  4. Test in non-prod environment first
  5. Ensure PDBs are configured for graceful node drain
  6. Back up cluster state (Velero or GitOps repo)
Upgrade Strategy Decision
FactorIn-PlaceBlue-Green
RiskLow-MediumLowest
CostNo extra2× during migration
Rollback❌ No CP rollback✅ Switch back
Use when✅ Most upgradesCritical workloads
Data Plane with Karpenter

Karpenter automatically replaces nodes via drift detection after control plane upgrade. Control the speed with disruption.budgets:

yaml
disruption:
  budgets:
  - nodes: "10%"  # Max 10% of nodes replaced at a time

For detailed upgrade guidance, see: Cluster Upgrades Reference

Autoscaling Quick Reference

Node Autoscaler Selection
KarpenterCluster AutoscalerAuto Mode
Default choice✅ YesLegacy/OutpostsMinimal ops
Scale-up speed~30s~60-90sAWS-managed
Consolidation✅ Built-in❌✅
CustomizationHighMediumLow
Show full SKILL.md (719 more words)Show less
Pod Autoscaler Selection
ScalerTriggerUse Case
HPACPU, memory, customStateless services
VPAHistorical usageRight-sizing (recommendation mode)
KEDAExternal events (SQS, Kafka)Event-driven workloads

For detailed autoscaling guidance, see: Autoscaling Reference | Karpenter Reference

Terraform Examples Quick Start

Based on terraform-aws-modules/terraform-aws-eks.

Example Selection
Starting PointRecommended Example
General productionkarpenter (MNG for system + Karpenter for workloads)
Minimal opseks-auto-mode
Managed nodeseks-managed-node-group (AL2023 or Bottlerocket)
Full node controlself-managed-node-group
Platform capabilitieseks-capabilities (ArgoCD, ACK, KRO)
Hybrid/edgeeks-hybrid-nodes
Common Deployment Topologies

Private cluster with Karpenter:

VPC (3 AZs, terraform-aws-modules/vpc/aws)
├── Private subnets → EKS nodes (MNG for system, Karpenter for workloads)
├── Public subnets  → ALB (internet-facing)
├── Intra subnets   → EKS control plane ENIs
└── NAT Gateway     → 1 per AZ for production

Multi-tenant platform:

EKS Cluster (terraform-aws-modules/eks/aws)
├── kube-system         (platform: CoreDNS, kube-proxy, VPC CNI)
├── karpenter           (Karpenter controller on MNG)
├── monitoring          (shared: Prometheus, Grafana)
├── ingress             (shared: AWS LBC)
├── team-a namespace    (RBAC, NetworkPolicy, ResourceQuota)
├── team-b namespace    (RBAC, NetworkPolicy, ResourceQuota)
└── team-c namespace    (RBAC, NetworkPolicy, ResourceQuota)

For detailed examples and terraform patterns, see: Terraform Examples Reference

Cost Optimization Quick Wins

ActionSavingsEffort
Graviton (arm64)20-40%Low
Spot for non-critical60-90%Low
Karpenter consolidation20-30%Low
VPA right-sizing15-30%Medium
gp3 over gp220% on EBSLow
VPC endpointsEliminate NAT costsLow

For detailed cost guidance, see: Cost Optimization Reference | For scalability guidance, see: Scalability Reference

Observability Quick Reference

PillarAWS-ManagedOpen Source
MetricsContainer InsightsAMP + Grafana
LogsCloudWatch LogsOpenSearch, Loki
TracesX-RayADOT + Jaeger/Tempo

Essential: Enable EKS audit logging and GuardDuty EKS Runtime Monitoring for security visibility.

For detailed observability guidance, see: Observability Reference

EKS Capabilities

EKS Capabilities are AWS-managed features installed and updated as part of the EKS platform. They run in AWS-owned infrastructure separate from your clusters, with AWS handling scaling, patching, and upgrading.

CapabilityWhat It DoesWhen to Use ManagedWhen to Self-Manage
ArgoCDGitOps continuous deliveryMulti-account hub-and-spoke, IAM IDC integration, minimal opsCustom plugins, air-gapped, existing ArgoCD investment
ACKManage AWS resources via K8s CRDs (S3, RDS, IAM, etc.)Standard AWS resource managementSpecific controller version pinning, custom config
KROPlatform abstractions via ResourceGroupDefinitionsGolden path templates, multi-resource compositionsEarly adoption risk concerns, custom reconciliation logic

Combined pattern: ArgoCD deploys ACK resources + KRO compositions via GitOps, providing a single workflow for both infrastructure and applications.

For detailed ArgoCD patterns, see: ArgoCD Patterns Reference

Sources:

Detailed References

This skill uses progressive disclosure — essential guidance is in this main file, detailed reference material is loaded on demand:

  • Security — IAM, Cluster Access Manager, Pod Identity, IRSA, pod security standards, multi-tenancy, secrets management, data encryption
  • Security — Runtime & Network — Runtime threat detection (GuardDuty, seccomp, AppArmor, Falco), network policies, SG for pods, encryption in transit, detective controls
  • Security — Supply Chain & Compliance — Image security (SBOMs, attestations, ECR hardening), infrastructure hardening (Bottlerocket, CIS benchmarks), regulatory compliance, incident response
  • Networking — VPC CNI modes (secondary IP, prefix delegation, custom networking), subnet/CIDR planning, IPv4 vs IPv6, Security Groups for Pods, IP address management
  • Networking — Ingress & DNS — Ingress patterns (ALB, NLB, Gateway API), AWS Load Balancer Controller, service mesh, DNS/CoreDNS tuning, private cluster connectivity
  • Reliability & Resiliency — Core — HA patterns, PDBs, health probes, load balancer health checks, lifecycle hooks, topology spread, resource management
  • Reliability & Resiliency — Advanced — disaster recovery, zonal shift, deployment strategies, large cluster guidance, chaos engineering, admission-controller topology enforcement
  • Autoscaling — Autoscaler selection, Cluster Autoscaler (IAM, Spot, overprovisioning, parameter tuning), HPA, VPA, KEDA, CoreDNS autoscaling
  • Karpenter — Operational best practices, NodePools, EC2NodeClass, Spot/interruption handling, consolidation, multiple NodePool strategy, cost controls, resource management, private clusters, CoreDNS with Karpenter
  • Cluster Upgrades — In-place and blue-green upgrades, pre-upgrade validation, add-on management, API deprecation detection, version skew policy, Bottlerocket updates, rollback procedures
  • Cost Optimization — CFM framework, compute/networking/storage cost strategies, observability cost management, Spot, Graviton, tagging, Kubecost
  • Scalability — Scaling theory (churn rate, QPS), control plane (APF, monitoring), data plane (node sizing, diversity), cluster services (CoreDNS, Metrics Server), workload patterns, IPVS, large-cluster guidance
  • Observability — Observability strategy, CloudWatch Container Insights & Application Signals, Prometheus/Grafana, control plane monitoring, network performance monitoring, logging architecture, distributed tracing, GPU/AI-ML observability, detective controls, alerting patterns
  • Terraform Examples — terraform-aws-modules/terraform-aws-eks examples, submodules, add-on management, Provisioned Control Plane, EFA, VPC patterns, deployment topologies
  • ArgoCD Patterns — ArgoCD architecture, App of Apps, ApplicationSets, GitOps Bridge, multi-cluster patterns (hub-and-spoke, decentralized, hybrid), EKS ArgoCD Capability (managed vs self-managed, migration), ACK/KRO integration, multi-tenant RBAC
  • Container Registry — ECR architecture, operating models, image promotion, vulnerability scanning, base image curation, lifecycle policies, pull-through cache, repository creation templates, managed signing (AWS Signer), archival storage class, registry configuration
  • EKS Auto Mode — Auto Mode architecture, managed NodePools/NodeClasses, migration from standard EKS, comparison with self-managed Karpenter, limitations and FAQ

How to use: When you need detailed information on a topic, reference the appropriate guide. Claude will load it on demand.

Sources

© aws-samples, MIT-0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 17 other files (references) in .kiro/skills/eks-best-practices of aws-samples/appmod-blueprints.

  • SKILL.md
  • references/argocd-patterns.md
  • references/autoscaling.md
  • references/cluster-upgrades.md
  • references/container-registry.md
  • references/cost-optimization.md
  • references/eks-auto-mode.md
  • references/karpenter.md
  • references/networking-ingress-dns.md
  • references/networking.md
  • references/observability.md
  • references/reliability-advanced.md
  • references/reliability-core.md
  • references/scalability.md
  • references/security-runtime-network.md
  • references/security-supply-chain.md
  • references/security.md
  • references/terraform-examples.md

Open the folder on GitHubat commit 42ea29c

Compare with similar skills

Eks Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Eks Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Eks Best Practices this skillaws-samples/appmod-blueprints113—~5kAutomated safety check: PassMIT-0
Cloud Devopsdavila7/claude-code-templates32k4 repos~1.4kAutomated safety check: PassMIT
Iac Securityhardw00t/ai-security-arsenal104—~2.4kAutomated safety check: PassNone
Agent Bom Scan InfraLeoYeAI/openclaw-master-skills2.2k—~1.5kAutomated safety check: PassApache-2.0
Discover Infrarand/cc-polymath181—~783Automated safety check: PassMIT
Platform Engineeringmagnus919/agent-skills113—~2.4kAutomated safety check: PassMIT

Similar skills

  • Cloud Devops

    davila7/claude-code-templates

    Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.

    32k GitHub starsUsed in 4 repos~1.4k tokens
    DevOps & CloudAuto-check passed
  • Iac Security

    hardw00t/ai-security-arsenal

    Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep.

    104 GitHub stars~2.4k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • Agent Bom Scan Infra

    LeoYeAI/openclaw-master-skills

    Scan infrastructure-as-code, cloud configurations, and find secrets.

    2.2k GitHub stars~1.5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Discover Infra

    rand/cc-polymath

    Automatically discover cloud, infrastructure, deployment, and container skills when working with AWS, GCP, Azure, Docker, Kubernetes, Terraform, Netlify, Heroku, serverless, or IaC

    181 GitHub stars~783 tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • Platform Engineering

    magnus919/agent-skills

    A skill your agent uses when building or operating internal developer platforms: infrastructure as code, CI/CD, container orchestration, service networking, secrets, and observability, or when…

    113 GitHub stars~2.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Devops Engineer

    Yikai-Liao/symusic

    Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.

    189 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check passed

More from aws-samples/appmod-blueprints

All 9 skills in this repo
  • Troubleshoot Platform

    aws-samples/appmod-blueprints

    Official

    Systematic troubleshooting for the PEEKS workshop platform — EKS clusters, Terraform state, ingress, load balancers, MCP tool failures, YAML validation.

    113 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Eks Recon

    aws-samples/appmod-blueprints

    Official

    EKS cluster reconnaissance and environment discovery. An agent skill from aws-samples/appmod-blueprints.

    113 GitHub stars~4.7k tokensUpdated today
    Auto-check: warnings
  • Troubleshoot Kro

    aws-samples/appmod-blueprints

    Official

    Troubleshoot Kro ResourceGraphDefinition (RGD) issues — stuck instances, ACK resource failures, IAM trust policy problems, resource conflicts.

    113 GitHub stars~986 tokensUpdated today
    Auto-check passed
  • Eks Upgrade Check

    aws-samples/appmod-blueprints

    Official

    Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade…

    113 GitHub stars~2.4k tokensUpdated today
    Auto-check: warnings
  • Eks Platform Engineering

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone is designing or building an Internal Developer Platform (IDP) or doing platform engineering on Amazon EKS — phrased as "build a developer platform"…

    113 GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    113 GitHub stars~4.7k tokensUpdated today
    Auto-check passed

Categories

Questions about Eks Best Practices

What does Eks Best Practices do?

Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning. Eks Best Practices is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.

When should I use Eks Best Practices?

Eks Best Practices fits situations like: any EKS planning; architectural judgment call; even when phrased casually; generating documents.

How do I install Eks Best Practices in Claude Code?

Run `npx skills add aws-samples/appmod-blueprints --skill eks-best-practices -a claude-code`. Or copy the skill folder (.kiro/skills/eks-best-practices in aws-samples/appmod-blueprints) into .claude/skills/eks-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Eks Best Practices in Codex?

Run `npx skills add aws-samples/appmod-blueprints --skill eks-best-practices -a codex`. Or copy the skill folder (.kiro/skills/eks-best-practices in aws-samples/appmod-blueprints) into .agents/skills/eks-best-practices in your project. Codex loads it when a task matches its description.

Can I use Eks Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws-samples/appmod-blueprints --skill eks-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/eks-best-practices, .gemini/skills/eks-best-practices, .github/skills/eks-best-practices and .opencode/skills/eks-best-practices in your project.

What does Eks Best Practices need to run?

SKILL.md names no scripts, command-line tools or credentials: Eks Best Practices is instructions for the agent only.

Does Eks Best Practices access the network?

SKILL.md names 3 domains. As links in the text: github.com, docs.aws.amazon.com and aws.amazon.com. This is read from the text; nothing was executed.

Is Eks Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Eks Best Practices use?

Eks Best Practices is published under the MIT-0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Eks Best Practices use?

About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 80k tokens, read only when the agent opens those files.

What are the alternatives to Eks Best Practices?

Skills that share tags, products or a category with Eks Best Practices: Cloud Devops (davila7/claude-code-templates, 32k stars), Iac Security (hardw00t/ai-security-arsenal, 104 stars), Agent Bom Scan Infra (LeoYeAI/openclaw-master-skills, 2.2k stars) and Discover Infra (rand/cc-polymath, 181 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Eks Best Practices?

aws-samples (a GitHub organization, an official publisher) maintains it in aws-samples/appmod-blueprints, which has 113 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: aws-samples/appmod-blueprints on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.