Skip to main content
Porter exposes advanced cluster configuration options for customers with specific compliance, security, or networking requirements. These settings are available on the Advanced tab of your cluster settings for AWS and GCP clusters.

Networking

Private cluster

When Private cluster is enabled, Porter provisions the EKS cluster with both public and private API server endpoint access, and restricts the public endpoint to an IP allowlist containing Porter’s control-plane IPs plus any customer CIDRs you add. This configuration is SOC2 / HIPAA compliant.
Porter intentionally does not enable EKS “private-only” endpoint mode. Private-only forces every control-plane call — including Porter’s — through a VPN or VPC-peered path, which adds operational complexity and has historically caused outages for customers. Public + private with a tight IP allowlist meets the same compliance requirements and is significantly more reliable.
The Tailscale integration is a separate layer that carries traffic for porter kubectl and porter helm commands; it does not control how the EKS API server endpoint itself is exposed.

Load balancer

Configure the type of load balancer used for your cluster’s ingress. Changing this setting causes downtime while the load balancer is recreated.When ALB is selected, the following additional settings become available. See Custom domains with ALB for end-to-end setup instructions.

Observability

CloudWatch control plane logs

Configure which EKS cluster control plane log types are sent to AWS CloudWatch. These logs help with debugging, auditing, and monitoring your cluster’s control plane components.

CloudWatch Observability agent

You may also enable the CloudWatch Observability agent as an EKS add-on for enhanced cluster monitoring.

Security

ECR scanning

Enable Amazon ECR image scanning to automatically scan container images for software vulnerabilities.

AWS GuardDuty

AWS GuardDuty provides intelligent threat detection for your EKS cluster, monitoring for malicious activity and unauthorized behavior.
When enabling GuardDuty, you must also configure the following in your AWS Console:
  1. Enable EKS Protection in the EKS Protection tab of the GuardDuty console
  2. Enable Runtime Monitoring
For automated agent configuration, enable both:
  • EKS agent auto-configuration
  • EC2 agent auto-configuration

KMS encryption

Enable AWS Key Management Service (KMS) encryption for Kubernetes secrets stored in etcd.