Low
EKS
Regional
EKS identity provider configurations should be tagged
Description
Flags Amazon EKS identity provider configurations that have no user-defined tags. Tags help associate IdP bindings with their owning team and downstream RBAC group mapping; untagged configurations are operationally opaque.
Remediation
Apply at least one user-defined tag to every EKS identity provider configuration.
Steps
- Open the Amazon EKS console and select the cluster.
- Choose Access, then Identity provider configurations.
- Select the configuration and choose Manage tags.
- Add at least one tag with a non-aws: prefixed key.
- Save the changes.