Amazon EKS now supports certificate authority (CA) rotation with automated lifecycle management

Published
August 20, 2026
https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-eks-certificate-authority-ca-rotation-automated-lifecycle-management

Amazon EKS Certificate Authority Rotation

Amazon EKS now offers certificate authority (CA) rotation, allowing customers to manage their cluster's CA lifecycle with automated safeguards. This feature ensures encrypted connections to the Kubernetes API remain secure and operational.

Key Points

  • Managed Lifecycle: Amazon EKS handles the rotation lifecycle and updates AWS-managed components.
  • Customer Responsibility: Customers must update worker nodes and external clients to trust the new CA.
  • Automated Safeguards: Features include advance notifications, automatic successor CA appending, and automatic activation.
  • Rollback Capability: Customers can revert to the previous CA if issues arise during the transition.

Availability

CA rotation is available at no additional cost in all commercial AWS Regions.

What to do

  • Use AWS CLI, EKS APIs, CloudFormation, or the AWS console to start CA rotation.
  • Update worker nodes and external clients to trust the new CA.

Source: AWS release notes




If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.

Follow our blog

Get the latest insights and advice on AWS services from our experts.

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.