Kubernetes compliance on EKS, AKS and GKE
Managed Kubernetes moves the control plane to the provider. Access to the cluster, what runs in it, how pods talk to each other and how fast you upgrade are still yours, and auditors increasingly ask.
A managed Kubernetes cluster passes a SOC 2 or ISO 27001 audit when cluster access goes through your cloud identity with RBAC mapped to groups, control plane audit logs are enabled and retained, images come from a scanned private registry, network policies restrict pod traffic, workloads run without privileged access, and the cluster stays on a supported version. The provider runs the control plane. You run everything above it.
Who is responsible for what
| Component | EKS | AKS | GKE |
|---|---|---|---|
| Control plane availability and patching | AWS | Microsoft | |
| Version upgrades | You trigger | You trigger or auto-upgrade channels | Release channels, auto-upgrade by default |
| Worker nodes | Managed node groups shared, Fargate by AWS | Node pools shared, node OS auto-upgrade available | Autopilot by Google, Standard shared |
| RBAC, workloads, images, network policy | You | You | You |
The controls auditors look at
- Cluster access
- EKS access entries or the aws-auth mapping to IAM roles; AKS with Entra ID integration and Azure RBAC; GKE with Google groups for RBAC. No shared kubeconfigs, no static tokens.
- Audit logging
- EKS control plane logging for audit and authenticator logs to CloudWatch, off by default; AKS diagnostic settings for kube-audit; GKE audit logs through Cloud Audit Logs.
- Image provenance
- Images from your own registry, scanned on push, with admission control rejecting unscanned or unsigned images.
- Pod security
- Pod Security Admission at the restricted or baseline level; no privileged containers or host mounts without a documented exception.
- Network policy
- Default deny between namespaces, explicit allows. Requires a network policy capable plugin.
- Secrets
- Envelope encryption of Kubernetes secrets with a KMS key, or secrets pulled from a cloud secret manager.
- Upgrades
- A supported Kubernetes version. Running a version past end of support is a vulnerability management finding.
Benchmarks
The CIS Kubernetes Benchmark and the provider-specific CIS benchmarks for EKS, AKS and GKE are the usual yardsticks. Defender for Containers, GKE security posture and third-party tools report against them. Treat them as a checklist, not a target score: an auditor wants the important items and a reason for each exception.
Is Kubernetes in scope for SOC 2?
If production workloads run on it, yes. The auditor will test access to the cluster, change management for deployments, logging and vulnerability management of the images, as part of CC6, CC7 and CC8.
Are EKS control plane logs on by default?
No. EKS control plane logging, including the audit log, must be enabled per cluster and sends logs to CloudWatch Logs, where you set retention.
Do we need a service mesh for compliance?
No. A mesh gives mutual TLS between services, which answers questions about encryption in transit inside the cluster. Network policies plus TLS at the edge and to databases satisfy most audits.
Running production on Kubernetes?
Firms in the network review clusters against CIS and prepare the evidence.
Get matched