Skip to main content
Porter exposes advanced cluster configuration options for customers with specific compliance, security, or networking requirements. These settings are available on the Advanced tab of your cluster settings for AWS, GCP, and Azure clusters.

Networking

Private cluster

When Private cluster is enabled, Porter provisions the EKS cluster with both public and private API server endpoint access, and restricts the public endpoint to an IP allowlist containing Porter’s control-plane IPs plus any customer CIDRs you add. This configuration is SOC2 / HIPAA compliant.
Porter intentionally does not enable EKS “private-only” endpoint mode. Private-only forces every control-plane call — including Porter’s — through a VPN or VPC-peered path, which adds operational complexity and has historically caused outages for customers. Public + private with a tight IP allowlist meets the same compliance requirements and is significantly more reliable.
The Tailscale integration is a separate layer that carries traffic for porter kubectl and porter helm commands; it does not control how the EKS API server endpoint itself is exposed.

Load balancer

Configure the type of load balancer used for your cluster’s ingress. Changing this setting causes downtime while the load balancer is recreated.When ALB is selected, the following additional settings become available. See Custom domains with ALB for end-to-end setup instructions.
Do not use this setting. Use the Application load balancer setting that follows. Porter continues to support this setting on clusters that already use it.

Application load balancer

This setting adds one more public ALB to the cluster. It does not replace the default load balancer of the cluster. Because each service selects the load balancer that serves it, you can move the domains one at a time.

Certificate validation

ACM validates the certificate with DNS. The ALB cannot serve traffic before the status of its certificate is ISSUED. While the status is pending, the cluster update continues to retry. The error message shows the records that ACM waits for.If you use Route53, Porter writes these records. Each root domain must have a hosted zone in the AWS account of the cluster.If you use Cloudflare, you must write these records. Find the CNAME name and the CNAME value of the certificate in the ACM console, in the region of the cluster. Then add these records to your zone. For the steps, refer to DNS validation.

Point DNS at the ALB

The ALB has its own address, so the records that point at the default load balancer do not change. For each root domain, point a wildcard record at the ALB, for example *.alb.example.com. On AWS, this address is a hostname, so you must use a CNAME record or a Route53 alias record. After Porter provisions the ALB, the address shows in the Custom domains area of the Networking tab of a service.

Web application firewall

Porter creates the web ACL with a default action of allow. Porter does not add rules. Add managed rule groups, rate-based rules, or IP sets in the AWS WAF console. Porter does not change these rules. Porter supports only Regional WAFv2.If you turn off this setting, Porter detaches the web ACL but does not delete it, so your rules remain if you turn on the setting again.

Route a service through the ALB

After the ALB serves traffic, the Networking tab of each web service shows a Public ALB option next to Public LB. In porter.yaml, use loadBalancers:
The domains of a service that the ALB serves must be below a registered root domain. When you change the load balancer of a service, the change takes effect at the next deployment. Move the DNS record of the domain to the address of the new load balancer.

Private load balancer

In addition to the default public cluster load balancer, you can provision an internal load balancer that only accepts traffic from inside your VPC (or networks peered to it). Use this when you want to expose services to internal clients, for example an internal admin tool, a service consumed only by other VPCs, or a workload that must not be reachable from the public internet.Once enabled, you must configure a DNS provider so Porter can issue and renew TLS certificates for ingress hostnames attached to the private load balancer. The following DNS providers are supported: Cloudflare and AWS Route53.
We recommend serving private ingress from a dedicated internal zone (for example, internal.example.com) rather than a zone that also serves production domains. This avoids record conflicts with production DNS and keeps DNS access scoped to internal hostnames only.If that isn’t practical, you can still keep credentials off your production zone. See Delegating certificate validation below.
Save the credentials before updating the cluster. You can rotate the token later with Edit credentials, or remove the integration entirely with Remove. Removing credentials stops certificate issuance and renewal for private load balancer ingress.

Delegating certificate validation

By default, the DNS credentials you give Porter need write access to the zone that hosts your private hostnames. If those hostnames live under a zone that also serves production domains, those credentials can reach your production records too, which is more privilege than you may want to grant.You can avoid that by delegating just the validation records to a separate, lower-privilege zone. You add a CNAME from each validation record in your zone to the delegated zone, then scope the credentials to that zone only. Porter handles the rest with no extra configuration on its side.
On AWS Route53 this isn’t necessary. Create a dedicated hosted zone for the subdomain and provide it as the Route53 domain (the Route53 option above); Porter scopes access to that zone directly.
1. Add the delegation CNAME records. Pick a low-privilege zone to hold the validation records (for example, acme.example-internal.com). In the zone that hosts your private hostnames, add a CNAME for each validation record, pointing at a record in the delegated zone:
2. Scope the credentials to the delegated zone. Create an API token scoped to the delegated zone only, with:
  • Zone.DNS → Edit
  • Zone.Zone → Read
The token does not need any access to your production zone.3. Verify the delegation. Confirm the CNAME resolves publicly:
Certificates are issued automatically when you attach a hostname to a service through its load balancer config. Porter then publishes each validation record into the delegated zone through the CNAME.If you need help setting this up, reach out to Porter support.

Observability

CloudWatch control plane logs

Configure which EKS cluster control plane log types are sent to AWS CloudWatch. These logs help with debugging, auditing, and monitoring your cluster’s control plane components.

CloudWatch Observability agent

You may also enable the CloudWatch Observability agent as an EKS add-on for enhanced cluster monitoring.

Security

ECR scanning

Enable Amazon ECR image scanning to automatically scan container images for software vulnerabilities.

AWS GuardDuty

AWS GuardDuty provides intelligent threat detection for your EKS cluster, monitoring for malicious activity and unauthorized behavior.
When enabling GuardDuty, you must also configure the following in your AWS Console:
  1. Enable EKS Protection in the EKS Protection tab of the GuardDuty console
  2. Enable Runtime Monitoring
For automated agent configuration, enable both:
  • EKS agent auto-configuration
  • EC2 agent auto-configuration

KMS encryption

Enable AWS Key Management Service (KMS) encryption for Kubernetes secrets stored in etcd.