AWS Security ChangesHomeSearch

AWS batch: Add EKS job definition Image pull secret and Namespace docs

Service: batch · 2026-09-27 · Documentation medium

File: batch/latest/userguide/create-job-definition-eks.md · Type: credentials

Summary

Adds optional Image pull secret and Namespace fields to the AWS Batch EKS job definition console instructions, including namespace restrictions and RBAC permission requirements. Renumbers subsequent steps.

Security assessment

The added text documents Kubernetes image pull secrets used for private registry credentials and notes RBAC requirements for alternate namespaces, which is security-relevant guidance but does not reference a specific vulnerability or incident.

Evidence

+    5. (Optional) For **Image pull secret** , enter the name of the Kubernetes Secret in the namespace where the job pod runs. The Secret contains credentials that Kubernetes uses to pull images from a private registry. The name can be up to 253 characters long. It can contain lowercase letters, numbers, hyphens (-), and periods (.), and must start and end with a letter or number.

Diff

diff --git a/batch/latest/userguide/create-job-definition-eks.md b/batch/latest/userguide/create-job-definition-eks.md
index ad553092b..8d39a373b 100644
--- a//batch/latest/userguide/create-job-definition-eks.md
+++ b//batch/latest/userguide/create-job-definition-eks.md
@@ -65 +65 @@ If a DNS policy isn't specified, **Default** isn't the default DNS policy. Inste
-    5. (Optional) For **Pod labels** , choose **Add pod labels** , then enter a name-value pair. 
+    5. (Optional) For **Image pull secret** , enter the name of the Kubernetes Secret in the namespace where the job pod runs. The Secret contains credentials that Kubernetes uses to pull images from a private registry. The name can be up to 253 characters long. It can contain lowercase letters, numbers, hyphens (-), and periods (.), and must start and end with a letter or number.
@@ -69 +69 @@ If a DNS policy isn't specified, **Default** isn't the default DNS policy. Inste
-The prefix for a pod label can't contain `kubernetes.io/`, `k8s.io/`, or `batch.amazonaws.com/`.
+The Secret must exist in the same namespace where the job pod runs.
@@ -71 +71 @@ The prefix for a pod label can't contain `kubernetes.io/`, `k8s.io/`, or `batch.
-    6. (Optional) For **Pod annotations** , choose **Add annotations** , then enter a name-value pair. 
+    6. (Optional) For **Namespace** , enter the Kubernetes namespace where AWS Batch places the job pod. This can be different from the Compute Environment's namespace. If the namespace provided here is different from the Compute Environment's namespace, you must configure equivalent AWS Batch role-based access control (RBAC) permissions in the job namespace. The namespace can be up to 63 characters long. It can contain lowercase letters, numbers, and hyphens (-), and must start and end with a letter or number. The namespace can't be `default` or start with `kube-`. If you don't specify a namespace, AWS Batch uses the compute environment's namespace.
@@ -73 +73 @@ The prefix for a pod label can't contain `kubernetes.io/`, `k8s.io/`, or `batch.
-###### Important
+    7. (Optional) For **Pod labels** , choose **Add pod labels** , then enter a name-value pair. The prefix for a pod label can't contain `kubernetes.io/`, `k8s.io/`, or `batch.amazonaws.com/`.
@@ -75 +75 @@ The prefix for a pod label can't contain `kubernetes.io/`, `k8s.io/`, or `batch.
-The prefix for a pod annotation can't contain `kubernetes.io/`, `k8s.io/`, or `batch.amazonaws.com/`.
+    8. (Optional) For **Pod annotations** , choose **Add annotations** , then enter a name-value pair. The prefix for a pod annotation can't contain `kubernetes.io/`, `k8s.io/`, or `batch.amazonaws.com/`.
@@ -77 +77 @@ The prefix for a pod annotation can't contain `kubernetes.io/`, `k8s.io/`, or `b
-    7. Choose **Next page**.
+    9. Choose **Next page**.
@@ -79 +79 @@ The prefix for a pod annotation can't contain `kubernetes.io/`, `k8s.io/`, or `b
-    8. In the **Container configuration** section:
+  12. In the **Container configuration** section:
@@ -105 +105 @@ Docker image architecture must match the processor architecture of the compute r
-    9. (Optional) You can add parameters to the job definition as name-value mappings to override the job definition defaults. To add a parameter:
+    6. (Optional) You can add parameters to the job definition as name-value mappings to override the job definition defaults. To add a parameter:
@@ -113 +113 @@ If you choose **Add parameter** , you must configure at least one parameter or c
-    10. In the **Environment configuration** section:
+    7. In the **Environment configuration** section:
@@ -123 +123 @@ To maximize your resource utilization, prioritize memory for jobs of a specific
-    11. (Optional) For **Environment variables** , choose **Add environment variable** to add environment variables as name-value pairs. These variables are passed to the container.
+    8. (Optional) For **Environment variables** , choose **Add environment variable** to add environment variables as name-value pairs. These variables are passed to the container.
@@ -125 +125 @@ To maximize your resource utilization, prioritize memory for jobs of a specific
-    12. (Optional) For **Volume mount** :
+    9. (Optional) For **Volume mount** :
@@ -135 +135 @@ To maximize your resource utilization, prioritize memory for jobs of a specific
-    13. (Optional) For **Run as user** , enter a user ID to run the container process.
+    10. (Optional) For **Run as user** , enter a user ID to run the container process.
@@ -141 +141 @@ The user ID must exist in the image for the container to run.
-    14. (Optional) For **Run as group** , enter a group ID to run the container process runtime.
+    11. (Optional) For **Run as group** , enter a group ID to run the container process runtime.
@@ -147 +147 @@ The group ID must exist in the image for the container to run.
-    15. (Optional) To give your job's container elevated permissions on the host instance (similar to the `root` user), drag the **Privileged** slider to the right. This parameter maps to `Privileged` in the [Create a container](https://docs.docker.com/engine/api/v1.38/#operation/ContainerCreate) section of the [Docker Remote API](https://docs.docker.com/engine/api/v1.38/) and the `--privileged` option to [**docker run**](https://docs.docker.com/engine/reference/commandline/run/).
+    12. (Optional) To give your job's container elevated permissions on the host instance (similar to the `root` user), drag the **Privileged** slider to the right. This parameter maps to `Privileged` in the [Create a container](https://docs.docker.com/engine/api/v1.38/#operation/ContainerCreate) section of the [Docker Remote API](https://docs.docker.com/engine/api/v1.38/) and the `--privileged` option to [**docker run**](https://docs.docker.com/engine/reference/commandline/run/).
@@ -149 +149 @@ The group ID must exist in the image for the container to run.
-    16. (Optional) Turn on **Read-only root filesystem** to remove write access to the root filesystem.
+    13. (Optional) Turn on **Read-only root filesystem** to remove write access to the root filesystem.
@@ -151 +151 @@ The group ID must exist in the image for the container to run.
-    17. (Optional) Turn on **Run as non-root** to run the containers in the pod as a non-root user.
+    14. (Optional) Turn on **Run as non-root** to run the containers in the pod as a non-root user.
@@ -157 +157 @@ If **Run as non-root** is turned on, the kubelet validates the image at runtime
-    18. Choose **Next page**.
+    15. Choose **Next page**.
@@ -159 +159 @@ If **Run as non-root** is turned on, the kubelet validates the image at runtime
-  12. For **Job definition review** , review the configuration steps. If you need to make changes, choose **Edit**. When you're finished, choose **Create job definition**.
+  13. For **Job definition review** , review the configuration steps. If you need to make changes, choose **Edit**. When you're finished, choose **Create job definition**.