QuestionQ6

Resilient Cloud Solutions

A DevOps engineer is building infrastructure for an application. The application must run on an Amazon Elastic Kubernetes Service (Amazon EKS) cluster that contains Amazon EC2 instances. The EC2 instances must use an Amazon Elastic File System (Amazon EFS) file system as their storage backend. The Amazon EFS Container Storage Interface (CSI) driver is installed on the EKS cluster.

When the DevOps engineer starts the application, the EC2 instances fail to mount the EFS file system.

Which solutions will resolve the problem?

Choose three
Explanation

EFS-backed Kubernetes volumes need an EFS mount target reachable from the EKS worker nodes, with the mount target’s security group allowing inbound NFS traffic on port 2049 from those nodes. The Amazon EFS CSI driver also needs IAM permissions to interact with the file system, such as permissions supplied by the AmazonEFSCSIDriverPolicy. A mount target must be available in the subnet/Availability Zone used by the EKS nodes.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!