Skip to main content
compliance · aws

EKS clusters whose managed node groups are all fixed in size

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Amazon EKS cluster when none of its managed node groups can scale, meaning every group returned by `eks:DescribeNodegroup` has `minSize` equal to `maxSize`. Fargate-only clusters are skipped. Clusters that scale through Karpenter or EKS Auto Mode on a small fixed node group can be flagged wrongly; dismiss those findings.

Signal and threshold

How ZopNight evaluates EKS clusters whose managed node groups are all fixed in size.
Field Value
Rule IDsRC-060
Categorycompliance
Severitymedium
Metricnone — pure configuration read
ThresholdminSize = maxSize on all managed node groups
SourceZopNight
Permissions usedeks:ListClusters · eks:ListNodegroups · eks:DescribeNodegroup

Node capacity that cannot move

Kubernetes can add pods faster than a fixed fleet can hold them. The EKS autoscaling page lists three ways to scale nodes: EKS Auto Mode, which creates and consolidates nodes and builds on Karpenter; Karpenter itself; and the Kubernetes Cluster Autoscaler, which works through Auto Scaling groups. For managed node groups, the Cluster Autoscaler never scales a group below minSize or above maxSize, so a group with equal values is pinned no matter what is installed. Pods that do not fit stay Pending, and the headroom you keep to avoid that is paid for around the clock.

Checking node group sizes

Terminal window
CLUSTER=my-cluster
for ng in $(aws eks list-nodegroups --cluster-name "$CLUSTER" --query 'nodegroups[]' --output text); do
aws eks describe-nodegroup --cluster-name "$CLUSTER" --nodegroup-name "$ng" \
--query 'nodegroup.[nodegroupName,scalingConfig.minSize,scalingConfig.maxSize]' --output text
done

Also check for Karpenter or Auto Mode before acting:

Terminal window
kubectl get nodepools 2>/dev/null

The node group test

ZopNight marks a cluster as autoscaling-enabled when at least one managed node group has a minimum size different from its maximum. The finding fires when that mark is explicitly false, meaning every managed node group is fixed. ZopNight has no setting to mark a cluster as scaled by something else, so a cluster whose node groups are all fixed is flagged whatever runs on it.

Clusters the rule cannot judge

Fargate-only clusters and Auto Mode clusters without managed node groups have no node group data, so the mark is never set and the rule stays silent.

The known blind spot is the AWS-documented pattern where Karpenter or EKS Auto Mode does the scaling and its controller runs on a small managed node group with minSize equal to maxSize. ZopNight cannot see the controller, so that cluster looks unscaled and is flagged. Dismiss the finding once you have confirmed the controller handles scaling.

Why the estimate is $0

No saving is attached. The cost is capacity held for peak, or pods left unscheduled at peak.

Turning on node autoscaling

  1. Pick an approach: Cluster Autoscaler, Karpenter or EKS Auto Mode.
  2. For Cluster Autoscaler, deploy it and give each managed node group a minSize lower than its maxSize, for example with aws eks update-nodegroup-config --cluster-name my-cluster --nodegroup-name NODEGROUP --scaling-config minSize=2,maxSize=10,desiredSize=2.
  3. For Karpenter, install the controller and create NodePool and EC2NodeClass resources.
  4. For EKS Auto Mode, enable compute, block storage and load balancing in one request, which AWS requires: aws eks update-cluster-config --name my-cluster --compute-config enabled=true --kubernetes-network-config '{"elasticLoadBalancing":{"enabled":true}}' --storage-config '{"blockStorage":{"enabled":true}}'.
  5. If Karpenter or Auto Mode already handles scaling, dismiss the finding in ZopNight.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·