7.6 Inter-Resource Encryption in Transit: Nitro, EMR, EKS & SageMaker AI

Key Takeaways

  • Supported Nitro instance types encrypt instance-to-instance traffic automatically in the same Region and the same or peered VPCs, but not through load balancers or transit gateways.

  • VPC Encryption Controls provide a monitor mode to find unencrypted traffic and an enforce mode that allows only encryption-capable resources, with chosen exclusions.

  • An Amazon EMR security configuration enables in-transit encryption on every node using TLS certificates from a PEM zip file in S3 or a custom provider.

  • Kubernetes doesn't encrypt pod traffic by default; use Nitro nodes, a service mesh with mTLS, CNI encryption, or VPC Lattice with TLS.

  • SageMaker AI inter-container traffic encryption protects distributed training traffic between instances and can increase training time.

Last updated: September 2026

7.6 Inter-Resource Encryption in Transit: Nitro, EMR, EKS & SageMaker AI

Encrypting the connection between a client and a load balancer is not enough when regulations require all traffic to be encrypted, including traffic between the nodes of a cluster. Skill 5.1.3, new in SCS-C03, asks you to design inter-resource encryption in transit for services such as Amazon EMR, Amazon EKS, and SageMaker AI, and to understand what AWS Nitro encryption provides automatically.


AWS Nitro Automatic Encryption in Transit

Supported Nitro-based instance types automatically encrypt traffic between instances using authenticated encryption with associated data (AEAD) and 256-bit keys, with no performance penalty and nothing to configure. The encryption applies only when all of these conditions hold:

  • Both instances use supported instance types.
  • The instances are in the same Region.
  • The instances are in the same VPC or in peered VPCs.
  • The traffic doesn't pass through a virtual network device or service, such as a load balancer or transit gateway.

Traffic that goes through an Application Load Balancer, a Network Load Balancer, or a transit gateway, or to an instance type without this support, must be protected with TLS or another protocol-level mechanism.

VPC Encryption Controls

VPC Encryption Controls give you visibility and enforcement at the VPC level. In monitor mode, you can see which traffic in the VPC is encrypted and which is not (for example, through VPC Flow Logs), which helps you find workloads that still send plaintext. In enforce mode, the VPC allows only resources that support encryption in transit, with explicit exclusions for components you choose, such as internet or NAT gateways. This turns "all traffic in this VPC is encrypted" from a documentation claim into an enforced property.


Amazon EMR

EMR clusters move large amounts of data between nodes during shuffles and replication. Encryption is configured in an EMR security configuration, which is attached to clusters at launch:

SettingWhat It Protects
In-transit encryptionEnables TLS and the open-source encryption features of cluster applications, such as Hadoop MapReduce encrypted shuffle, Spark RPC and block transfer encryption, and Presto or Trino internal communication
Certificate providerTLS certificates supplied as PEM files in a zip archive in Amazon S3, or a custom certificate provider class
At-rest encryption (related)EMRFS data in S3 with SSE-S3, SSE-KMS, or client-side encryption, and local disk encryption with a KMS key

Because a security configuration applies to every node, it is the answer when a question requires encryption between EMR nodes without changing application code. Pair it with Nitro-supported instance types for defense in depth.


Amazon EKS

Kubernetes doesn't encrypt pod-to-pod traffic by default. Options, from least to most work:

  1. Nitro instance encryption: Worker nodes on supported instance types automatically encrypt traffic between nodes in the same VPC, but not traffic through load balancers or between pods on the same node.
  2. Service mesh mutual TLS: A mesh such as Istio issues workload certificates and encrypts and authenticates every service-to-service connection, which also provides identity-based authorization.
  3. CNI-level encryption: Network plugins such as Cilium or Calico can encrypt node-to-node traffic with WireGuard or IPsec.
  4. Amazon VPC Lattice: Service-to-service networking with TLS listeners and IAM-based auth policies, without running a mesh.
  5. Application-level TLS: Services terminate TLS themselves, often with certificates issued by AWS Private CA through cert-manager.

The EKS control plane API endpoint always uses TLS, and envelope encryption of Kubernetes secrets with KMS protects data at rest, not in transit.


Amazon SageMaker AI

Distributed training jobs exchange model parameters and gradients between ML compute instances. Set EnableInterContainerTrafficEncryption to true on training (and hyperparameter tuning) jobs to encrypt that inter-node traffic. It can increase training time and cost because of the encryption overhead. Related controls:

  • EnableNetworkIsolation blocks the training container from making outbound network calls.
  • VPC configuration keeps training and inference traffic in your subnets, with VPC endpoints for S3 and SageMaker APIs.
  • Inference endpoints are accessed over HTTPS; KMS keys encrypt storage volumes and model artifacts at rest.

Other Services with Internal Encryption Settings

ServiceInter-Node or Internal Setting
Amazon OpenSearch ServiceNode-to-node encryption (TLS within the domain); once enabled it can't be disabled
Amazon MSKEncryption within the cluster (broker to broker) and a client-broker setting of TLS, TLS and plaintext, or plaintext
Amazon ElastiCache (Valkey, Redis OSS)In-transit encryption for client and replication traffic
Amazon DocumentDB / Amazon NeptuneTLS for client connections, enforced through cluster parameters

Choosing the Right Answer

  • "Encrypt traffic between EC2 instances in the same VPC with no application changes and no performance impact": Nitro-supported instance types.
  • "Encrypt Spark shuffle and block transfer between EMR nodes": EMR security configuration with in-transit encryption.
  • "Encrypt communication between instances in a SageMaker AI distributed training job": inter-container traffic encryption.
  • "Mutually authenticate and encrypt microservice traffic in EKS": service mesh mTLS (or VPC Lattice with TLS and auth policies).
  • "Prove every flow in the VPC is encrypted, and block non-compliant resources": VPC Encryption Controls.

Specialty Exam Pitfalls

  1. Assuming Nitro encryption covers load balancer or transit gateway paths: It doesn't; use TLS for those hops.
  2. Forgetting the certificate source for EMR: In-transit encryption needs certificates in S3 (PEM zip) or a custom provider.
  3. Confusing at-rest and in-transit controls: KMS encryption of EKS secrets, EBS volumes, or SageMaker volumes doesn't encrypt network traffic.
  4. Ignoring cost and performance notes: SageMaker inter-container encryption can lengthen training; exam answers may mention this tradeoff.
Loading diagram...
Inter-Resource Encryption in Transit Options
Test Your Knowledge

A healthcare analytics company runs Apache Spark on Amazon EMR. Auditors require that data moving between cluster nodes during shuffles and block transfers be encrypted, and the data engineering team can't change application code. What should the security engineer do?

A

Enable SSE-KMS on the S3 bucket that stores input data.

B

Create an EMR security configuration with in-transit encryption, supply TLS certificates as a PEM zip file in S3, and launch the clusters with that configuration.

C

Place the cluster nodes in a private subnet with a restrictive network ACL.

D

Enable EBS encryption by default in the account.

Test Your Knowledge

A company wants traffic between EC2 instances in the same VPC to be encrypted without deploying certificates, changing applications, or adding latency. Some of this traffic currently flows through an internal Application Load Balancer. What should the security engineer conclude?

A

Nitro encryption covers all traffic in the VPC, including traffic through the load balancer.

B

Encryption between instances always requires IPsec tunnels between every pair of instances.

C

Supported Nitro instance types automatically encrypt direct instance-to-instance traffic in the same VPC, but traffic through the ALB must still be protected with TLS (HTTPS listeners and HTTPS target groups).

D

Only VPC Flow Logs can encrypt traffic between instances.

Test Your Knowledge

A machine learning team runs distributed SageMaker AI training jobs across multiple instances on sensitive financial data. Compliance requires that model parameters exchanged between training instances be encrypted in transit. Which setting meets this requirement?

A

Enable inter-container traffic encryption (EnableInterContainerTrafficEncryption) on the training job, accepting that training may take longer.

B

Enable network isolation (EnableNetworkIsolation) on the training job.

C

Encrypt the training job's output with a customer managed KMS key.

D

Store the training data in S3 with DSSE-KMS.

Test Your Knowledge

A regulated company must demonstrate that all traffic within a production VPC is encrypted in transit and must prevent teams from launching resources that can't encrypt traffic, apart from the VPC's NAT gateway. Which approach meets this requirement with the least ongoing effort?

A

Review VPC Flow Logs manually each week for plaintext ports.

B

Require every team to deploy a service mesh on EC2 instances.

C

Attach an SCP that denies ec2:RunInstances for all instance types.

D

Enable VPC Encryption Controls, starting in monitor mode to find unencrypted flows, then switch to enforce mode with an exclusion for the NAT gateway.

Sections you finish are checked off in the contents.