Skip to content

Commit e88c4d3

Browse files
committed
Stage eks mcp server docs for launch
1 parent bcdb346 commit e88c4d3

File tree

6 files changed

+1140
-0
lines changed

6 files changed

+1140
-0
lines changed

latest/ug/doc-history.adoc

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,13 @@ https://docs.aws.amazon.com/eks/latest/userguide/doc-history.rss
1919
[.updates]
2020
== Updates
2121

22+
[.update,date="2025-11-21"]
23+
=== New {aws} managed policy
24+
[.update-ulink]
25+
link:eks/latest/userguide/security-iam-awsmanpol.html#security-iam-awsmanpol-updates[type="documentation"]
26+
27+
Amazon EKS has released a new managed policy `AmazonEKSMCPReadOnlyAccess` to enable read-only tools in the Amazon EKS MCP Server for observability and troubleshooting. For information, see link:eks/latest/userguide/security-iam-awsmanpol.html#security-iam-awsmanpol-updates[Amazon EKS updates to {aws} managed policies,type="documentation"].
28+
2229
[.update,date="2025-11-19"]
2330
=== Network observability
2431
[.update-ulink]

latest/ug/security/iam-reference/security-iam-awsmanpol.adoc

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -231,6 +231,26 @@ The policy also includes several condition checks to ensure that the permissions
231231

232232
To view the latest version of the JSON policy document, see link:aws-managed-policy/latest/reference/AmazonEKSLoadBalancingPolicy.html#AmazonEKSLoadBalancingPolicy-json[AmazonEKSLoadBalancingPolicy,type="documentation"] in the {aws} Managed Policy Reference Guide.
233233

234+
[#security-iam-awsmanpol-amazoneksmcpreadonlyaccess]
235+
== {aws} managed policy: AmazonEKSMCPReadOnlyAccess
236+
:info_titleabbrev: AmazonEKSMCPReadOnlyAccess
237+
238+
You can attach `AmazonEKSMCPReadOnlyAccess` to your IAM entities. This policy provides read-only access to Amazon EKS resources and related {aws} services, enabling the Amazon EKS Model Context Protocol (MCP) Server to perform observability and troubleshooting operations without making any modifications to your infrastructure.
239+
240+
*Permissions details*
241+
242+
This policy includes the following permissions that allow principals to complete the following tasks:
243+
244+
* *`eks`* &endash; Allows principals to describe and list EKS clusters, node groups, add-ons, access entries, insights, and access the Kubernetes API for read-only operations.
245+
* *`iam`* &endash; Allows principals to retrieve information about IAM roles, policies, and their attachments to understand the permissions associated with EKS resources.
246+
* *`ec2`* &endash; Allows principals to describe VPCs, subnets, and route tables to understand the network configuration of EKS clusters.
247+
* *`sts`* &endash; Allows principals to retrieve caller identity information for authentication and authorization purposes.
248+
* *`logs`* &endash; Allows principals to start queries and retrieve query results from CloudWatch Logs for troubleshooting and monitoring.
249+
* *`cloudwatch`* &endash; Allows principals to retrieve metric data for monitoring cluster and workload performance.
250+
* *`eks-mcp`* &endash; Allows principals to invoke MCP operations and call read-only tools within the Amazon EKS MCP Server.
251+
252+
To view the latest version of the JSON policy document, see link:aws-managed-policy/latest/reference/AmazonEKSMCPReadOnlyAccess.html[AmazonEKSMCPReadOnlyAccess,type="documentation"] in the {aws} Managed Policy Reference Guide.
253+
234254
[#security-iam-awsmanpol-amazoneksservicepolicy]
235255
== {aws} managed policy: AmazonEKSServicePolicy
236256
:info_titleabbrev: AmazonEKSServicePolicy
@@ -430,6 +450,11 @@ https://github.com/awsdocs/amazon-eks-user-guide/commits/mainline/latest/ug/secu
430450
|Change
431451
|Description
432452
|Date
453+
454+
|Introduced <<security-iam-awsmanpol-amazoneksmcpreadonlyaccess>>.
455+
|Amazon EKS introduced new managed policy `AmazonEKSMCPReadOnlyAccess` to enable read-only tools in the Amazon EKS MCP Server for observability and troubleshooting.
456+
|November 21, 2025
457+
433458
|Added permissions to <<security-iam-awsmanpol-amazonebscsidriverservicerolepolicy,AmazonEBSCSIDriverPolicy>>.
434459
|Added `ec2:CopyVolumes` permission to allow the EBS CSI Driver to copy EBS volumes directly.
435460
|November 17, 2025

0 commit comments

Comments
 (0)