<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Eks on Confidential Containers</title>
    <link>/zh-cn/tags/eks/</link>
    <description>Recent content in Eks on Confidential Containers</description>
    <generator>Hugo</generator>
    <language>zh-cn</language>
    <copyright>© The Linux Foundation. All rights reserved. The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our &lt;a href=&#34;https://www.linuxfoundation.org/trademark-usage/&#34;&gt;Trademark Usage&lt;/a&gt; page.</copyright>
    <atom:link href="/zh-cn/tags/eks/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>AWS</title>
      <link>/zh-cn/docs/examples/aws-simple/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>/zh-cn/docs/examples/aws-simple/</guid>
      <description>&lt;blockquote&gt;&#xA;&lt;p&gt;&lt;strong&gt;说明：&lt;/strong&gt; 本文为英文文档的中文译版，英文原版请参见 &lt;a href=&#34;https://confidentialcontainers.org/docs/examples/aws-simple/&#34;&gt;AWS 示例（英文版）&lt;/a&gt;。&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;本文将介绍如何在 AWS Elastic Kubernetes Service (EKS) 上配置 CAA（即 Peer Pods），具体包括：&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;一个基于 Elastic Kubernetes Service (EKS) 的单工作节点 Kubernetes 集群&lt;/li&gt;&#xA;&lt;li&gt;运行在该 Kubernetes 集群上的 CAA&lt;/li&gt;&#xA;&lt;li&gt;一个由 CAA PodVM 支撑的 Nginx Pod&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;前提条件&#34;&gt;前提条件&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#%e5%89%8d%e6%8f%90%e6%9d%a1%e4%bb%b6&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;安装所需工具：&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;安装 &lt;a href=&#34;https://kubernetes.io/docs/tasks/tools/#kubectl&#34;&gt;kubectl&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;安装 &lt;a href=&#34;https://helm.sh/docs/intro/install&#34;&gt;Helm&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;安装 &lt;code&gt;aws&lt;/code&gt; CLI &lt;a href=&#34;https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html&#34;&gt;工具&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;安装 &lt;code&gt;eksctl&lt;/code&gt; CLI &lt;a href=&#34;https://eksctl.io/installation/&#34;&gt;工具&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;确保已安装 &lt;code&gt;curl&lt;/code&gt;、&lt;code&gt;git&lt;/code&gt; 和 &lt;code&gt;jq&lt;/code&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;aws-准备工作&#34;&gt;AWS 准备工作&lt;a class=&#34;td-heading-self-link&#34; href=&#34;#aws-%e5%87%86%e5%a4%87%e5%b7%a5%e4%bd%9c&#34; aria-label=&#34;Heading self-link&#34;&gt;&lt;/a&gt;&lt;/h2&gt;&lt;ul&gt;&#xA;&lt;li&gt;为 AWS CLI 访问设置 &lt;code&gt;AWS_ACCESS_KEY_ID&lt;/code&gt;、&lt;code&gt;AWS_SECRET_ACCESS_KEY&lt;/code&gt;（或 &lt;code&gt;AWS_PROFILE&lt;/code&gt;）以及 &lt;code&gt;AWS_REGION&lt;/code&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;&lt;strong&gt;说明：&lt;/strong&gt; 除了静态凭证外，也可以在 EKS 上使用 &lt;a href=&#34;/zh-cn/docs/examples/aws-simple/#%e9%85%8d%e7%bd%ae%e8%ae%a4%e8%af%81&#34;&gt;IRSA（IAM Roles for Service Accounts）&lt;/a&gt;。使用 IRSA 时，CAA Pod 通过 OIDC 完成认证，无需在 Kubernetes Secret 中保存静态 AWS 密钥。集群初始化步骤中仍然需要 &lt;code&gt;AWS_REGION&lt;/code&gt; 和临时凭证。&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
