aws AWS What's New ·

Amazon EKS now supports certificate authority (CA) rotation with automated management

securityawsgaengineeraws-eks
feature

Amazon Elastic Kubernetes Service (EKS) has introduced certificate authority (CA) rotation, allowing customers to rotate their cluster's CA through a managed lifecycle. This feature helps maintain operational continuity and security, especially for clusters nearing the 10-year validity period of their original CAs. While EKS manages the rotation and updates AWS-managed components, customers are responsible for replacing worker nodes and updating external clients. The service includes automated safeguards, advance notifications, and a rollback capability, and is available at no additional cost in all commercial AWS Regions.

Features (1)
  • Amazon EKS adds managed certificate authority rotation

    Amazon EKS now supports rotating cluster certificate authorities (CAs), ensuring secure and operational Kubernetes API connections as CAs approach their 10-year expiry. The process involves shared responsibility, with AWS managing the rotation lifecycle and customers updating worker nodes and external clients. Automated safeguards, including advance notifications and a rollback option, are provided to assist with the transition.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-eks-certificate-authority-ca-rotation-automated-lifecycle-management

Related releases