Skip to main content
compliance · aws

EKS Cluster Autoscaling Not Configured

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

EKS clusters whose managed node groups all pin MinSize equal to MaxSize have no visible autoscaling and get a $0 advisory. Karpenter or EKS Auto Mode hosted on a fixed-size node group looks identical, so operators can set autoscaling_managed_externally=true to suppress the finding; Fargate-only clusters are never stamped.

Signal and threshold

How ZopNight evaluates EKS Cluster Autoscaling Not Configured.
Field Value
Rule IDsRC-060
Categorycompliance
Severitymedium
Metricnone — pure configuration read
Sourceeks_autoscaling.go

Node group scaling config and its blind spot

  • Metadata: autoscaling_enabled (bool): the EKS discoverer’s annotateAutoscalingEnabled (eks.go) stamps this per cluster: true when any managed node group’s ScalingConfig has MinSize != MaxSize. Only stamped when the cluster has at least one managed node group (Fargate-only clusters leave the key absent).
  • Metadata (optional operator override): autoscaling_managed_externally (bool), set explicitly to true to suppress the rule for a cluster confirmed to autoscale via a controller the discoverer cannot see (Karpenter, EKS Auto Mode) hosted on a fixed-size managed node group. the discoverer’s only signal is managed node group ScalingConfig. A cluster running Karpenter or EKS Auto Mode for elastic scaling, with the controller hosted on a small fixed-size managed node group (MinSize == MaxSize, the AWS-documented topology), is indistinguishable from a cluster with no autoscaling at all and will fire until either the autoscaling_managed_externally override is set on the resource or the discoverer gains a Karpenter/EKS Auto Mode presence signal (not yet implemented).

Why no dollar figure is attached

fixed estimate: $0/mo

Picking an autoscaler, or declaring one

  1. Choose an autoscaling solution: Cluster Autoscaler, Karpenter, or EKS Auto Mode
  2. For Cluster Autoscaler: deploy via Helm and configure node group min/max sizes (set MinSize != MaxSize)
  3. For Karpenter: install the controller and create NodePool + EC2NodeClass manifests
  4. For EKS Auto Mode: enable in cluster settings (API: UpdateClusterConfig)
  5. If autoscaling is already handled by Karpenter/EKS Auto Mode on a fixed-size managed node group, set autoscaling_managed_externally=true on the resource to suppress this rule

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·