Networking & Security — VPCs, IAM & Access Control

Networking problems in AWS are often invisible until something stops working — a pod can't pull from ECR, a service can't reach the database, or a deployment stalls because no nodes are available in the right availability zone. This category covers the networking and security decisions that affect production reliability: choosing between VPC Peering and Transit Gateway, configuring IRSA for pod-level AWS access without static credentials, and diagnosing why pods can't be scheduled due to topology constraints.

VPC Subnets Security Groups NACLs IAM IRSA TLS NetworkPolicy Transit Gateway PrivateLink

Connectivity & Scheduling Issues

Network-related failures that prevent pods from running or reaching their dependencies.

FIX
Fix EKS Node Not Joining Cluster

Fix EKS worker nodes that won't join — aws-auth ConfigMap, IAM policies, bootstrap errors, VPC endpoints, and security group configuration.

FIX
Fix AWS Security Group Misconfiguration

Diagnose and fix security group rules causing connection timeouts — VPC flow logs, NACLs, and Reachability Analyzer.

FIX
Fix EKS Pod Cannot Access Internet

Fix EKS pods with no outbound connectivity — NAT Gateway, route tables, DNS, and CNI plugin.

FIX
Fix AWS Load Balancer Not Routing Traffic

Resolve ALB/NLB routing failures — target health checks, security group rules, and listener configuration.

FIX
Fix Nginx 404 on Refresh (SPA Routing)

Fix Nginx 404s on SPA route refresh — try_files for React, Vue, Angular in standalone, Docker, and Kubernetes.

FIX
Fix Kubernetes Ingress Not Working

Ingress not routing traffic — Ingress controllers, IngressClass, TLS secrets, backend endpoints, and path types.

FIX
Fix X-Forwarded-For Not Showing Real IP

Fix XFF header not passing real client IP — Nginx, AWS ALB/NLB Proxy Protocol, and Ingress Controller ConfigMap.

FIX
Fix DNS Resolution Issues in Kubernetes

CoreDNS failures, OOMKilled DNS pods, port 53 NetworkPolicy blocks, dnsPolicy issues, and ndots latency.

FIX
Fix Internal Service Communication Failure in Kubernetes

Pods can't reach internal Services — selector, port, NetworkPolicy, kube-proxy, and cross-namespace FQDN.

FIX
Pod Pending: No Nodes Available

Diagnose pods stuck in Pending — covering insufficient resources, taints, node selectors, affinity rules, and PVC binding failures.

FIX
ECR Login Failed: Fix AWS ECR Authentication

Fix expired tokens, IAM permission errors, cross-account access issues, and misconfigured credential helpers for AWS ECR.

Networking & IAM Architecture Guides

Architecture decisions and implementation guides for secure AWS networking.

Browse by topic

Every article on DevOps Compass is organized into a focused category.