CoreNova Intelligence

AWS Marketplace · EKS administration host

Standardize Amazon EKS administration without a public SSH bastion

Deploy an Amazon Linux 2023 administration host with AWS CLI v2, kubectl, Helm, eksctl, and k9s already installed, then connect through AWS Systems Manager Session Manager.

SSM-first

Boundaries you can verify before buying

The SSM path can run with no inbound rule

With SSM connectivity and an instance role in place, no inbound rule is required; configure restricted SSH only as an optional fallback.

Credentials stay in your AWS account

The image contains no passwords, private keys, AWS credentials, kubeconfigs, or customer data.

Auditable tool inventory

A local inventory records installed tool versions, with corenova-eks-check as a local diagnostic command.

AWS · IAM · EKS

How it works

1. Subscribe and deploy

Subscribe to the matching architecture in AWS Marketplace and place the instance in a private subnet with AWS API connectivity.

2. Review and scope access

Attach SSM and EKS permissions that you have reviewed and scoped; you configure EKS Access Entries and Kubernetes RBAC.

3. Operate through SSM

Open a Session Manager shell, generate kubeconfig, and use kubectl, Helm, eksctl, or k9s.

AL2023

Included in the image

  • Amazon Linux 2023 with SSH, audit, logging, time-sync, firewall, AIDE baseline, and Amazon SSM Agent
  • AWS CLI v2 with no customer credentials or kubeconfig baked in
  • Multi-version kubectl selector, Helm, eksctl, k9s, kubectx, and kubens
  • Starter IAM, EKS Access Entry, and operator examples to review and scope
  • Tool inventory, MOTD quickstart, and local diagnostic command

Security and responsibility boundary

This is an EKS administration-host AMI, not an EKS worker-node image. Buyers own IAM permissions, EKS Access Entries, Kubernetes RBAC, network egress, log retention, patch policy, and workload security. With SSM connectivity, an instance role, and private-subnet egress in place, inbound SSH is not required. The Marketplace standalone launch flow still displays a private TCP 22 fallback recommendation; remove it for SSM-only access. Operators install the Session Manager plugin on their workstation. Anyone who can open a shell on the host can use its EC2 instance-role credentials and inherits that role's EKS permissions, so this is a trusted-admin boundary rather than per-user EKS identity isolation.

Current purchase terms

The software fee is $0.04 per running instance-hour and the product is currently available only in us-east-1. EC2, EBS, NAT Gateway, VPC endpoints, networking, and other AWS infrastructure are billed separately by AWS. The current public offer has no free trial; live Marketplace terms take precedence.

Want to check the fit before deploying?

Tell us your cluster region, access model, and current bastion workflow. We can start with a 20-minute architecture walkthrough before you deploy.

Book a 20-minute walkthrough