AWS has a wide surface area, and most DevOps problems on EKS come down to three things: IAM permissions, network configuration, and authentication. This category covers the AWS services you'll actually touch when running containerised workloads — from setting up IRSA for pod-level IAM roles to fixing ECR authentication failures, to making the right call between VPC Peering and Transit Gateway.
Troubleshooting
The most common AWS errors that surface when running Kubernetes workloads.
Work through every S3 authorization layer — IAM ARNs, bucket policy, Block Public Access, Object Ownership, and KMS key permissions.
Diagnose security group rules causing silent timeouts — VPC flow logs, NACLs, EKS rules, and Reachability Analyzer.
Fix EKS pods with no outbound connectivity — NAT Gateway, route tables, DNS, and security group egress rules.
Resolve ALB/NLB traffic routing failures — target health checks, security groups, and EKS Load Balancer Controller.
Fix AWS AccessDenied errors — missing IAM actions, IRSA misconfiguration, resource policies, SCPs, and ECR token pitfalls.
Fix EKS worker nodes that won't join — aws-auth ConfigMap, missing IAM node policies, bootstrap script errors, and VPC connectivity.
Fix expired tokens, IAM permission errors, cross-account access issues, and misconfigured credential helpers for AWS ECR.
Guides
Decision frameworks and step-by-step guides for AWS infrastructure.
All Categories
Every article on DevOps Compass is organized into a focused category.
Pod lifecycle, workloads, probes, scheduling, and production cluster operations.
EKS, IAM, ECR, VPC architecture, and cost-aware infrastructure decisions.
Jenkins, GitLab CI, GitHub Actions, deployment strategies, and automation.
Docker, image security, registries, and container runtime debugging.
Prometheus, Grafana, Loki, alerting, and observability for production.
VPCs, IAM, TLS, network policies, and access control patterns.