Português ↗
Nodefort

Production-ready EKS in one afternoon, not weeks

Terraform kit with IAM, Graviton node groups, encryption, IRSA, and ExternalSecrets already configured to the standard senior SRE teams use — stop rebuilding the same checklist from scratch on every new project.

No spam. One email when the kit ships, with an early-access discount.

Thanks — you're on the list. We'll let you know when it ships.

nodefort — zsh

What ships ready

Hardened control plane

Private endpoint by default, full CloudWatch logging, KMS-encrypted secrets.

Graviton-first

ARM64 node groups (m7g) as the default — 20-30% better cost/performance — with an easy x86 fallback.

No SSH, no keys

Bottlerocket + mandatory IMDSv2 + auditable access via SSM Session Manager.

Modular IRSA

IAM roles scoped to namespace+serviceaccount, never inheriting the node's role.

Secrets without the drama

External Secrets Operator with least-privilege policy, never secretsmanager:* on *.

GitOps-ready

Outputs ready to bootstrap ArgoCD or Flux — endpoint, CA, OIDC provider.

Who it's for

Small platform teams and consultancies who stand up production EKS for different clients and are tired of rebuilding the same security checklist every time. If your team already has a full-time senior SRE, you probably already have this — this kit is for the ones who don't.