EKS Hybrid Nodes Best Practices
2 min read
Amazon EKS Hybrid Nodes connects servers in on-premises and edge infrastructure as worker nodes of the AWS-managed EKS control plane. This guide is a reference that organizes, as per-area best practices, the technical issues that repeatedly arise when designing, building, and operating hybrid clusters — CIDR design, architecture decisions, Hybrid Nodes Gateway, firewall pre-registration, node authentication, storage and registry, and GPU workloads. The intended audience is infrastructure architects, platform engineers, and security staff preparing firewall and network registration requests.
Document Structure
Overview & ArchitectureHybrid Nodes concepts, how it works, key technical characteristics, and a guide to the six design decisions — connectivity, topology, Pod CIDR exposure, and moreNetworkingCIDR design and address-range minimization, CNI configuration and Pod CIDR routing, Hybrid Nodes Gateway, load balancing, firewall pre-registration and TGW topology, air-gapped VPC endpointsSecurity & AuthenticationChoosing a node authentication method — SSM hybrid activation vs IAM Roles Anywhere, credential lifecycle managementStorage & RegistryShared file storage (EFS, FSx, NFS) solutions and Harbor private container registry integrationCompute & GPU3-tier architecture for hybrid GPU workloads, GPU taint isolation, Device Plugin, cloud fallback, DGX H200 SR-IOV and InfiniBand high-performance networkingOperations & CostMixed Mode operational patterns, Cluster Insights configuration validation, observability integration (eBPF, Container Insights), upgrades and lifecycle, and cost optimization based on vCPU-hour billing