eks-securitylisted
Install: claude install-skill aws-samples/sample-apex-skills
# EKS Security & Compliance
End-to-end, opinionated security and compliance guidance for Amazon EKS, structured as a **7-layer stack** plus a **compliance-regime cross-cutting view**. This skill is **discovery-driven** — the right hardening stack is a function of *(compliance regime × OS-standardization mandate × team skill × audit timeline × workload sensitivity × air-gap requirement × scale × operational-overhead tolerance)*. Skipping the discovery questions makes the recommendation wrong about half the time.
Two AWS-published guides are the canonical foundation and every recommendation must align with one or both: the [EKS Best Practices: Compliance](https://docs.aws.amazon.com/eks/latest/best-practices/compliance.html) guide and the [EKS Best Practices: Runtime Security](https://docs.aws.amazon.com/eks/latest/best-practices/runtime-security.html) guide. For "how do I run a single cluster well" (non-security) use `eks-best-practices`; for designing/building the cluster use `eks-design` / `eks-build`.
> **The accuracy bar (non-negotiable for this skill).** Compliance is the one domain where customers validate *every* claim against an auditor. **Compliance status changes over time — always defer to the live [AWS Services in Scope](https://aws.amazon.com/compliance/services-in-scope/) page before quoting program coverage** in any customer-facing document. Never state a cryptographic-module status, FedRAMP boundary, or certification you cannot cite to an AWS-published sourc