惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Privacy & Cybersecurity Law Blog
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
B
Blog RSS Feed
罗磊的独立博客
V
V2EX
V
Visual Studio Blog
博客园 - 叶小钗
W
WeLiveSecurity
小众软件
小众软件
K
Kaspersky official blog
美团技术团队
雷峰网
雷峰网
阮一峰的网络日志
阮一峰的网络日志
Martin Fowler
Martin Fowler
Recorded Future
Recorded Future
Project Zero
Project Zero
Hugging Face - Blog
Hugging Face - Blog
Engineering at Meta
Engineering at Meta
Security Latest
Security Latest
Microsoft Azure Blog
Microsoft Azure Blog
V
Vulnerabilities – Threatpost
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
Help Net Security
Help Net Security
博客园 - Franky
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
F
Fortinet All Blogs
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Forbes - Security
Forbes - Security
M
MIT News - Artificial intelligence
H
Hacker News: Front Page
大猫的无限游戏
大猫的无限游戏
Vercel News
Vercel News
Spread Privacy
Spread Privacy
The Register - Security
The Register - Security
H
Hackread – Cybersecurity News, Data Breaches, AI and More
量子位
Google Online Security Blog
Google Online Security Blog
PCI Perspectives
PCI Perspectives
The Last Watchdog
The Last Watchdog
AI
AI
N
News | PayPal Newsroom
D
DataBreaches.Net
Cloudbric
Cloudbric
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 司徒正美
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tailwind CSS Blog

AWS for Industries

How Axel Springer transformed ad monetization by migrating from client-side bidding to AWS RTB Fabric | Amazon Web Services How Peloton Engineers the World’s Largest Live Fitness Events on AWS | Amazon Web Services Henry Schein One goes AI-native with AI Product Discovery and Strategy | Amazon Web Services Cloud Adoption Update for Financial Market Infrastructure Providers 1H26 | Amazon Web Services How AWS helps Hong Kong banks deliver on HKMA DART Framework | Amazon Web Services GreenBridge.AI redefines renewable energy operations with agentic AI on AWS | Amazon Web Services Build a voice-enabled Automotive and Manufacturing assistant using Amazon Nova Sonic and Amazon Bedrock AgentCore | Amazon Web Services Managing AI agent sprawl across business units | Amazon Web Services Dynamic Inbound Routing for BYOIP Workloads Using Amazon VPC Route Server | Amazon Web Services How Autel Transformed Charging Station Management with AI Agents on AWS | Amazon Web Services Build a Multi-Agent Assessment Workbench with Amazon Bedrock AgentCore | Amazon Web Services Sovereign by design: How AWS helps Nigeria’s financial services industry protect data and drive innovation | Amazon Web Services Scaling ML in production: how BBVA accelerated delivery with MLOps | Amazon Web Services Inside BBVA’s MLOps transformation: from data platform to scalable ML on AWS | Amazon Web Services Blazing a Trail: How Peloton Rebuilt the SDLC for the Agentic Era with Amazon Bedrock | Amazon Web Services Accelerate RISC-V Software Development Before Silicon: Virtual Prototyping with MachineWare’s SIM-V on AWS | Amazon Web Services How retailers deliver hyper-personalization in-store with Personalisation Hub, UST, and AWS | Amazon Web Services Deploy diagnostic-quality imaging globally with MedDream and AWS HealthImaging | Amazon Web Services Coins in Motion: Building agentic blockchain payments for in-vehicle experiences | Amazon Web Services Reduce P&ID analysis time by 80% with hybrid AI maintenance planning | Amazon Web Services Deploying industrial AI on AWS: Building the autonomous factory | Amazon Web Services How Atlantic Health cut legal document search time by 42% with Amazon Bedrock metadata filtering | Amazon Web Services Edge-to-Cloud Architecture for Real-Time Surgical Intelligence with AWS and NVIDIA | Amazon Web Services Reimagining B-Pillar DFMEA: Why Ontology-Grounded AI Is the Future of Automotive Engineering | Amazon Web Services Transforming energy trading by managing complexity and driving growth with Cloud ETRM | Amazon Web Services How Multi-Agent AI Turns Supply Chain Data into Decisions and Actions | Amazon Web Services ​​​Deploy Agentic Bidding Without Sacrificing Speed: ARTF Containers with NVIDIA GPU Acceleration on AWS​​ | Amazon Web Services Next-generation programmatic advertising: How AWS RTB Fabric redefines the game | Amazon Web Services Flexible Telecom AI Workload Deployment Across AWS Hybrid Cloud | Amazon Web Services Building a HIPAA-ready generative AI architecture for healthcare on AWS | Amazon Web Services Highlights from the 2026 AWS Life Sciences Symposium: MedTech Track | Amazon Web Services Multi-Agent Systems for Financial Services on Amazon EKS and AgentCore | Amazon Web Services How AI can help developers migrate embedded codebases between Arm SoCs | Amazon Web Services From Connected to Resilient: Cloud-Native Payment Connectivity on AWS | Amazon Web Services Ultra-low-latency cross-Region crypto trading with Avelacom and AWS | Amazon Web Services Build an AI-powered 5G Signaling Trace Analyzer Using Amazon Bedrock | Amazon Web Services Medical Legal Regulatory Review Orchestration with AI Agents on AWS | Amazon Web Services AWS showcases the agentic AI future of advertising and entertainment at Cannes Lions 2026 | Amazon Web Services The Road to 180M GRefs/s: Sizing Epic on AWS with R8ib and Enhanced EBS | Amazon Web Services BridgeWise builds responsible AI in FSI with Amazon Bedrock | Amazon Web Services Rethink Everything: Highlights from the 2026 AWS Financial Services Symposium | Amazon Web Services Improving Defect Analysis and Quality Control with AI Diagnostics | Amazon Web Services Building a cloud-based EV charging monitoring platform with real-time AI analytics | Amazon Web Services Introducing the AWS guide to the ECB Guide on outsourcing cloud services to cloud service providers | Amazon Web Services How a Luxury Retailer Accelerates Customer Experience with Amazon CloudFront | Amazon Web Services The Art of the Possible: Building an Intelligent Wealth Management Platform – Part 1 | Amazon Web Services How We Built Healthcare AI You Can Trust: The Science Behind Amazon Connect Health | Amazon Web Services How Everllence Scaled P&ID Intelligence to Improve Plant Operations | Amazon Web Services Rivian accelerates production with second-generation AWS Outposts: Improving resiliency and reducing costs | Amazon Web Services AI-Driven Development Lifecycle for Financial Services | Amazon Web Services How Agentic AI and Digital Twins on AWS Drive Operational Excellence | Amazon Web Services Modernizing Core Banking Systems: A Strategic Guide for Financial Leaders | Amazon Web Services Highlights from the 2026 AWS Life Sciences Symposium: Research and Drug Discovery | Amazon Web Services Discount Tire Uses Cloud WAN and Buffer VPC to Create a Scalable Enterprise Network Centralized third-party connectivity in AWS: Architecture patterns for highly regulated environments | Amazon Web Services FHIR-powered Care Continuum on AWS HealthLake From code to chemistry: using Kiro to tackle ADME-Tox, a key drug discovery challenge | Amazon Web Services How Toyota securely deployed HiveMQ with mTLS on AWS to power Smart Manufacturing | Amazon Web Services From record to intelligence: How EMR systems on AWS become the foundation for generative AI in healthcare | Amazon Web Services How to Connect AWS HealthOmics to Public and Private Network Sources at Runtime | Amazon Web Services Accelerating Android Builds on AWS: From 3 Hours to Under 5 Minutes with SourceFS | Amazon Web Services Closing the Loop with Amazon Bio Discovery’s Integrated Lab Partners | Amazon Web Services Massive Parallel Processing of Financial Transactions with Amazon EKS and Amazon MSK | Amazon Web Services Submit up to 100,000 Bioinformatics Workflow Runs with a Single API Call in AWS HealthOmics | Amazon Web Services Energy HPC Orchestrator powers collaborative, scalable energy computing | Amazon Web Services Automate Investment Research Using Strands Agents on Bedrock AgentCore | Amazon Web Services How OCC Built a Governed Cloud Foundation and Then Stress-Tested It Executive Insights from the 2026 AWS Life Sciences Symposium How Carlsberg’s Traitomic business leveraged AWS HealthOmics to power genetic trait development | Amazon Web Services CME Group MDP multicast data access on AWS using Transit Gateway | Amazon Web Services How retailers solve the customer identity puzzle with Amperity and AWS | Amazon Web Services Exact Sciences Transforms Bioinformatics Infrastructure with AWS HealthOmics | Amazon Web Services Building a Serverless Supply Chain Management Solution for Automotive Customers with AWS AppSync and Amazon Aurora Serverless | Amazon Web Services Accelerating physical AI with AWS and NVIDIA: building production-ready applications with simulation and real-world learning | Amazon Web Services Modernizing life-saving workloads with AWS serverless | Amazon Web Services Transforming Industrial Operations: How AVEVA and AWS drive Cloud Innovation | Amazon Web Services Introducing Amazon Bio Discovery | Amazon Web Services Accelerate Project Delivery with AI-Native Execution System on Amazon Quick | Amazon Web Services Reinvent Telecom Mediation Systems with Amazon Bedrock AgentCore, Strands Agents, and the Model Context Protocol | Amazon Web Services AWS Cloud Connectivity Patterns for Financial Market Infrastructures | Amazon Web Services Event-Driven Digital Pathology: Governed Whole Slide Image Ingestion to Scalable Inference with Amazon SageMaker | Amazon Web Services How Telefonica Germany achieved a centralized tracing solution with VPC Traffic Mirroring | Amazon Web Services AWS Teams Up with Wingstop to Deliver Wings to Millions During March Hoops Tournament | Amazon Web Services How Amazon Connect Health brings agentic AI to the point of care | Amazon Web Services How Liftoff improved conversion performance and reduced infrastructure costs with Cortex using AWS Graviton | Amazon Web Services From Prompt to Pipeline: AI-Powered Bioinformatics Workflow Development with Kiro and AWS HealthOmics | Amazon Web Services Driving Intelligent Quality in the Software-Defined Vehicle Era | Amazon Web Services How Amazon Devices Eliminated Credential Risk to Scale AI across Engineering Tools | Amazon Web Services The Evolution of BMW Group’s 3D Streaming Experience | Amazon Web Services Build ChatGPT Apps with MCP Servers and AWS Infrastructure | Amazon Web Services
How Danone Simplified Kubernetes at Scale with Amazon EKS Auto Mode | Amazon Web Services
Ali Sanhaji · 2026-07-15 · via AWS for Industries

Danone, one of the world’s leading food and beverage companies, operates a global cloud infrastructure supporting critical workloads across research and innovation, supply chain, and digital platforms. Their Cloud-Native Engineering team manages a growing fleet of Amazon Elastic Kubernetes Service (Amazon EKS) clusters across multiple AWS accounts and regions.

As their Kubernetes footprint expanded, so did the operational burden—and the team needed a way to simplify without sacrificing control. In this post, we walk through how Danone adopted Amazon EKS Auto Mode to reduce operational overhead, strengthen security, and optimize costs.

The challenge: running Kubernetes at scale

Danone’s Cloud-Native Engineering team had built a mature, production-grade Kubernetes platform. Their clusters ran hundreds of pods serving public-facing and enterprise applications, including a Digital Health and R&I platform running front-end applications and APIs that support their medical studies ecosystem. The team had invested heavily in Terraform modules, CI/CD pipelines, and operational runbooks to keep everything running smoothly. But as the number of clusters and workloads grew, the team found itself spending more time maintaining the platform than improving it. What had started as manageable infrastructure work was becoming a bottleneck—every new cluster meant more node groups to tune, more add-ons to track, and more security configurations to audit. The challenges were clear:

  • Manual add-on management—The AWS Load Balancer Controller, Amazon EBS CSI Driver, and Amazon EKS Pod Identity Agent each had their own upgrade cycle and compatibility matrix. These add-ons consumed node capacity and required constant attention.
  • Kubernetes upgrades were a project, not a routine—Upgrading clusters was a multi-week effort. Some clusters had fallen behind into extended support—at six times the cost of standard support.
  • Security compliance required manual effort—Meeting Danone’s cybersecurity standards meant manually configuring and auditing node settings, runtime policies, and patching schedules across every cluster.
  • Node optimization was difficult with Managed Node Groups—Managed Node Groups made it hard to adapt instance types and scaling to the actual needs of each workload. The team couldn’t easily right-size nodes per application, resulting in clusters that were not optimized and consistently underutilized.
  • Complex infrastructure as code—Each cluster required extensive Terraform to manage node groups, networking, IAM roles, and add-on versions. Changes were slow and error-prone.

The platform team wanted to focus on enabling development teams—but the operational tax of running Kubernetes kept pulling them back.

How EKS Auto Mode changes the equation

Amazon EKS Auto Mode fundamentally shifts the operational boundary. Instead of managing node groups, add-ons, and scaling policies, the platform team defines what their applications need—and Auto Mode handles the infrastructure underneath.

At the compute layer, Auto Mode manages nodes through Karpenter, which provisions right-sized instances on demand, bin-packs workloads efficiently, and consolidates underutilized capacity automatically. Critical add-ons—the Load Balancer Controller, EBS CSI Driver, and Pod Identity Agent—become AWS-managed, eliminating manual version tracking entirely. Nodes are based on Bottlerocket, a purpose-built, immutable, and security-hardened operating system designed specifically for running containers. With SELinux in enforcing mode, read-only root file systems, and a 21-day maximum node lifetime, the security baseline is built into the platform rather than layered on top.

For Danone, this meant a dramatically reduced operational scope—instead of managing infrastructure, add-ons, and scaling, the team could concentrate on their workloads, freeing them to invest in developer experience, application reliability, and business value.

From exploration to production

Danone’s migration to EKS Auto Mode took approximately nine months, from initial exploration to full production rollout across their cluster fleet.

The journey started with a hands-on immersion day where the platform team evaluated Auto Mode’s capabilities in a controlled environment—testing node provisioning, add-on management, and security defaults against their existing Terraform-managed setup. The team came away with a clear understanding of what migration would involve and confidence that Auto Mode could meet their production requirements.

Some of the production clusters to migrate had several hundred pods, which required a careful, incremental approach rather than a big-bang cutover. The team migrated applications one by one from legacy Auto Scaling Groups to Auto Mode nodes, controlling the blast radius at each step and validating behavior before proceeding. During the transition, they ran the legacy ALB Ingress Controller alongside the Auto Mode-managed controller simultaneously, shifting traffic gradually before decommissioning the old load balancers—avoiding any disruption to production. The Load Balancer Controller, EBS CSI Driver, and Pod Identity Agent were consolidated into their Auto Mode managed equivalents, freeing up node capacity that these components had previously consumed.

Figure 1—Danone’s EKS architecture before and after Auto Mode

Figure 1—Danone’s EKS architecture before and after Auto Mode

In Figure 1, on the left, Danone administers Managed Node Groups with a fixed fleet of M6i instances, along with critical add-ons (EKS Pod Identity, EBS CSI Driver, AWS Load Balancer Controller). On the right, Managed Node Groups are replaced by Karpenter, which automatically selects and right-sizes a diverse set of instance types (C6a, M6i, C7g). Add-ons are now AWS-managed and updated automatically. Danone’s responsibility shrinks to application pods only.

Once the migration approach was validated, the team rolled Auto Mode across their remaining clusters. Terraform configurations for node groups and scaling policies were replaced with simple YAML manifests, and the extended support backlog was cleared entirely. The new architecture enables the platform team to concentrate on application-level concerns—deployment strategies, observability, and developer self-service—rather than infrastructure plumbing.

The benefits

By offloading node management, add-on lifecycle, and scaling to Auto Mode, the platform team reclaimed over 20% of their operational capacity. Kubernetes version upgrades went from multi-week projects to routine operations, and infrastructure as code went from complex Terraform modules to straightforward YAML manifests. The team now spends that recovered time on capabilities that directly serve their development teams.

On the security front, Auto Mode’s Bottlerocket-based nodes align with Danone’s cybersecurity standards out of the box. The team no longer maintains a separate hardening playbook for each cluster—immutable AMIs, SELinux enforcing, and automatic node rotation provide a compliant baseline from the moment a cluster is created.

Cost optimization came through Karpenter’s automated bin-packing, which drives node utilization to 80–90%, up from variable and often underutilized levels. Combined with Savings Plans and the elimination of extended support costs, the team achieved all the operational and security benefits of Auto Mode with no additional cost—the efficiency gains fully offset the Auto Mode management fee.

The migration also produced improvements beyond the primary goals: certificate autodiscovery using AWS Certificate Manager (ACM)—eliminating the need to hardcode certificate ARNs in Ingress manifests and simplifying pipeline management—better resource tagging and security group integration through Kubernetes manifests, and a cleaner ingress architecture with clear separation between application and infrastructure concerns.

Conclusion

In nine months, Danone went from managing every layer of their Kubernetes infrastructure—node groups, add-ons, scaling policies, security hardening—to a model where the platform team focuses almost entirely on applications and developer experience. EKS Auto Mode eliminated the undifferentiated heavy lifting that had consumed over 20% of the team’s capacity, while Karpenter’s automated bin-packing pushed node utilization to 80–90% and Bottlerocket-based nodes delivered a security baseline that meets enterprise compliance standards out of the box.

Any organization running Amazon EKS at scale—whether managing a handful of clusters or dozens across multiple accounts and regions—can follow a similar incremental path. The migration doesn’t require a big-bang cutover: start with one cluster, move workloads application by application, and expand once the approach is validated. The operational and security benefits compound with every cluster migrated—without increasing costs.

Get started with EKS Auto Mode

Ready to simplify your Kubernetes operations? Start here:

To discuss how EKS Auto Mode fits your Kubernetes strategy, reach out to your AWS account team or contact AWS.

The authors would like to thank Alberto Colombo, Lead Platform Engineer at Danone, who led the hands-on implementation of the EKS Auto Mode migration across Danone’s cluster fleet.