{"repo":"opszero/terraform-aws-kubespot","free":true,"listed":false,"github":"https://github.com/opszero/terraform-aws-kubespot","clone":"git clone https://github.com/opszero/terraform-aws-kubespot.git","description":"Compliance-ready Kubernetes on AWS EKS with SOC2 and HIPAA support","language":"HCL","stars":117,"topics":["kubernetes","hipaa","pci","ami","packer","aws","aws-ec2","kops","soc2"],"license":null,"category":"deployment-docker-iac","readme_excerpt":"Kubespot (AWS) AWS EKS Setup for PCI-DSS, SOC2, HIPAA Kubespot is AWS EKS customized to add security postures around SOC2, HIPAA, and PCI compliance. It is distributed as an open source terraform module allowing you to run it within your own AWS account without lock-in. Kubespot has been developed over a half a decade evolving with the AWS EKS distribution and before that kops. It is in use within multiple startups that have scaled from a couple founders in an apartment to billion dollar unicorns. By using Kubespot they were able to achieve the technical requirements for compliance while being able to deploy software fast. Kubespot is a light wrapper around AWS EKS. The primary changes included in Kubespot are: - Locked down with security groups, private subnets and other compliance related requirements. - Locked down RDS and Elasticache if needed. - Users have a single Load Balancer through which all requests go through to reduce costs. - KEDA is used for scaling on event metrics such as queue sizes, user requests, CPU, memory or anything else Keda supports. - Karpenter is used for autoscaling. - Instance are lockdown with encryption, and a regular node cycle rate is set. Tools & Setup Cluster Usage If the infrastructure is using the opsZero infrastructure as code template then you access the resources like the following: Add your IAM credentials in /.aws/credentials . Autoscaler Kubespot uses Karpenter as the default autoscaler. To configure the autoscaler we need to create","default_branch":null,"files":null,"tree":[],"storefront":"/r/opszero","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/opszero/terraform-aws-kubespot/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}