The k8s cluster is placed on our VPC on some specifics subnets. Also AWS assign to the cluster a security group that allow us to configure inbound connections and outbound connections. Also this security group can be configured to allow connections from our cluster to another services that use security groups.
This configuration can be found in EKS configuration using the command line or the graphic user interface.