EKS Learning Plan — Native Ubuntu 26.04 Host, Single-Host Local Cluster
Revision: targets a native Ubuntu 26.04 LTS (“Resolute Raccoon”) workstation.
No WSL, no Git Bash, no second machine. One host runs the control plane and the
worker nodes for all local work; AWS runs the control plane only during paid EKS
sessions.
Model: the EKS cluster is cattle. It exists only while you are actively typing
into it. Idle cost target is $0.00/day.
ZPA is a cloud-delivered Zero Trust Network Access (ZTNA) service that brokers
per-application access between users and private applications, without ever
placing those applications on the public internet or putting the user on the
corporate network.
Core components
Component
Where it runs
Role
Client Connector (Z-App)
User’s device
Authenticates the user against your IdP and checks device posture before requesting a session
Policy engine (Central Authority)
Zscaler cloud
Evaluates identity, device posture, group membership, time of day, etc. and authorizes (or denies) each session
Service Edge (Public / Private / Microtenant)
Zscaler cloud (or your site, for Private Service Edge)
Brokers the connection — stitches the user’s tunnel and the App Connector’s tunnel together
App Connector
Your data center or cloud VPC, next to the app
Lightweight VM/container that dials outbound to the Service Edge; never accepts inbound connections
How a connection is brokered
The Client Connector authenticates the user and checks device posture, then dials outbound to the Service Edge.
The App Connector, sitting next to the private application, also dials outbound to the Service Edge.
The Service Edge stitches these two outbound-only streams together into a single brokered session, after the Policy engine has authorized it.
No inbound port is ever opened on either side — the app has no public IP, no public DNS record, and isn’t discoverable by internet scanners.
This “double inside-out tunnel” is what lets ZPA give a user access to exactly
one authorized application instead of broad network reach, the way a VPN
would.