Skip to main content

EKS Hybrid Nodes Best Practices

Published 2025-02-05Updated 2026-08-252 min read

Amazon EKS Hybrid Nodes connects servers in on-premises and edge infrastructure as worker nodes of the AWS-managed EKS control plane. This guide is a reference that organizes, as per-area best practices, the technical issues that repeatedly arise when designing, building, and operating hybrid clusters โ€” CIDR design, architecture decisions, Hybrid Nodes Gateway, firewall pre-registration, node authentication, storage and registry, and GPU workloads. The intended audience is infrastructure architects, platform engineers, and security staff preparing firewall and network registration requests.


Document Structureโ€‹

๐Ÿงญ
Overview & Architecture
Hybrid Nodes concepts, how it works, key technical characteristics, and a guide to the six design decisions โ€” connectivity, topology, Pod CIDR exposure, and more
๐ŸŒ
Networking
CIDR design and address-range minimization, CNI configuration and Pod CIDR routing, Hybrid Nodes Gateway, load balancing, firewall pre-registration and TGW topology
๐Ÿ”
Security & Authentication
Choosing a node authentication method โ€” SSM hybrid activation vs IAM Roles Anywhere, credential lifecycle management
๐Ÿ’พ
Storage & Registry
Shared file storage (EFS, FSx, NFS) solutions and Harbor private container registry integration
โšก
Compute & GPU
3-tier architecture for hybrid GPU workloads, DGX H200 SR-IOV and InfiniBand high-performance networking
๐Ÿ“Š
Operations & Cost
Mixed Mode operational patterns, Cluster Insights configuration validation, monitoring, and cost optimization based on vCPU-hour billing