Amazon EKS now supports certificate authority (CA) rotation with automated lifecycle management

Amazon EKS Certificate Authority Rotation
Amazon EKS now offers certificate authority (CA) rotation, allowing customers to manage their cluster's CA lifecycle with automated safeguards. This feature ensures encrypted connections to the Kubernetes API remain secure and operational.
Key Points
- Managed Lifecycle: Amazon EKS handles the rotation lifecycle and updates AWS-managed components.
- Customer Responsibility: Customers must update worker nodes and external clients to trust the new CA.
- Automated Safeguards: Features include advance notifications, automatic successor CA appending, and automatic activation.
- Rollback Capability: Customers can revert to the previous CA if issues arise during the transition.
Availability
CA rotation is available at no additional cost in all commercial AWS Regions.
What to do
- Use AWS CLI, EKS APIs, CloudFormation, or the AWS console to start CA rotation.
- Update worker nodes and external clients to trust the new CA.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



