<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="https://wiki.quizz.vn/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="https://wiki.quizz.vn/feed.php">
        <title>Wiki.Quizz.vn - aws:containers:eks:pod</title>
        <description></description>
        <link>https://wiki.quizz.vn/</link>
        <image rdf:resource="https://wiki.quizz.vn/lib/exe/fetch.php?media=wiki:dokuwiki.svg" />
       <dc:date>2026-04-15T19:53:56+00:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="https://wiki.quizz.vn/doku.php?id=aws:containers:eks:pod:aws-permissions&amp;rev=1766908155&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.quizz.vn/doku.php?id=aws:containers:eks:pod:networking&amp;rev=1766908177&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.quizz.vn/doku.php?id=aws:containers:eks:pod:no-direct-iam-policy&amp;rev=1766909003&amp;do=diff"/>
                <rdf:li rdf:resource="https://wiki.quizz.vn/doku.php?id=aws:containers:eks:pod:service-account-binding&amp;rev=1766908135&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="https://wiki.quizz.vn/lib/exe/fetch.php?media=wiki:dokuwiki.svg">
        <title>Wiki.Quizz.vn</title>
        <link>https://wiki.quizz.vn/</link>
        <url>https://wiki.quizz.vn/lib/exe/fetch.php?media=wiki:dokuwiki.svg</url>
    </image>
    <item rdf:about="https://wiki.quizz.vn/doku.php?id=aws:containers:eks:pod:aws-permissions&amp;rev=1766908155&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-12-28T07:49:15+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>aws-permissions</title>
        <link>https://wiki.quizz.vn/doku.php?id=aws:containers:eks:pod:aws-permissions&amp;rev=1766908155&amp;do=diff</link>
        <description>Pod AWS Permissions (Node Role vs IRSA)

What it is: How a Pod gets permissions to call AWS APIs (S3, DynamoDB, etc.).

What it’s for:

	*  Enforce least privilege for each workload.

Two common models:

1) Node IAM Role (EC2 Instance Profile)

	*</description>
    </item>
    <item rdf:about="https://wiki.quizz.vn/doku.php?id=aws:containers:eks:pod:networking&amp;rev=1766908177&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-12-28T07:49:37+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>networking</title>
        <link>https://wiki.quizz.vn/doku.php?id=aws:containers:eks:pod:networking&amp;rev=1766908177&amp;do=diff</link>
        <description>Pod Networking Basics

What it is: How Pods communicate with each other and the outside network in Kubernetes/EKS.

What it’s for:

	*  Enable service-to-service communication in a microservices architecture.
	*  Control traffic using Kubernetes Services and network policies (when available).</description>
    </item>
    <item rdf:about="https://wiki.quizz.vn/doku.php?id=aws:containers:eks:pod:no-direct-iam-policy&amp;rev=1766909003&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-12-28T08:03:23+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>no-direct-iam-policy</title>
        <link>https://wiki.quizz.vn/doku.php?id=aws:containers:eks:pod:no-direct-iam-policy&amp;rev=1766909003&amp;do=diff</link>
        <description>EKS Pods: No “Direct IAM Policy on Pod”

What it is: Clarification that AWS does not natively attach an IAM *policy* directly to a Pod.

What it’s for:

	*  Correct a common misconception in exam answers.

Key ideas:

	*  In EKS, the standard least-privilege approach is:</description>
    </item>
    <item rdf:about="https://wiki.quizz.vn/doku.php?id=aws:containers:eks:pod:service-account-binding&amp;rev=1766908135&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2025-12-28T07:48:55+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>service-account-binding</title>
        <link>https://wiki.quizz.vn/doku.php?id=aws:containers:eks:pod:service-account-binding&amp;rev=1766908135&amp;do=diff</link>
        <description>Pod ↔ Service Account Binding

What it is: The relationship between a Pod and the Kubernetes Service Account (SA) it uses.

What it’s for:

	*  Decide which identity the Pod uses inside Kubernetes.
	*  Enable mapping from Pod → SA → IAM Role (with IRSA).</description>
    </item>
</rdf:RDF>
