# Fixing EKS overprivileged cluster settings

_The cluster creator gets admin by default. Now you can take it back without a rebuild._

Are you aware that your Amazon EKS cluster could be at risk due to a default permission setting? By default, the IAM role that creates an EKS cluster is granted the **_system:master_** RBAC role, providing broad administrative access. This could be a significant security concern.

In the past, rectifying this issue was a cumbersome process, often requiring the recreation of the entire cluster. But now, AWS has streamlined this with new cluster access management APIs. With a simple command:

```bash
aws eks delete-access-entry --cluster-name <CLUSTER_NAME> --principal-arn <IAM_PRINCIPAL_ARN>
```

you can adjust these permissions efficiently without the need to recreate the cluster.

This development is a game-changer in EKS cluster security management, aligning with the principle of least privilege access. It's crucial for EKS users to be aware of these changes and implement them to ensure their clusters are secure.

For more detailed steps and insights on this topic, make sure to read the full AWS blog post [here](https://aws.amazon.com/blogs/containers/a-deep-dive-into-simplified-amazon-eks-access-management-controls/).