Amazon EKS now supports certificate authority (CA) rotation with automated management
Amazon Elastic Kubernetes Service (EKS) has introduced certificate authority (CA) rotation, allowing customers to rotate their cluster's CA through a managed lifecycle. This feature helps maintain operational continuity and security, especially for clusters nearing the 10-year validity period of their original CAs. While EKS manages the rotation and updates AWS-managed components, customers are responsible for replacing worker nodes and updating external clients. The service includes automated safeguards, advance notifications, and a rollback capability, and is available at no additional cost in all commercial AWS Regions.
Features (1) ›
- Amazon EKS adds managed certificate authority rotation
Amazon EKS now supports rotating cluster certificate authorities (CAs), ensuring secure and operational Kubernetes API connections as CAs approach their 10-year expiry. The process involves shared responsibility, with AWS managing the rotation lifecycle and customers updating worker nodes and external clients. Automated safeguards, including advance notifications and a rollback option, are provided to assist with the transition.
https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-eks-certificate-authority-ca-rotation-automated-lifecycle-management
Related releases
- Amazon EKS Capability for Argo CD adds custom configuration support AWS What's New ·
- AWS Local Zone in Las Vegas, Nevada, Now Generally Available AWS What's New ·
- Amazon EKS Introduces Managed Certificate Authority Rotation with Safeguards AWS Containers Blog ·
- Amazon EKS now supports advanced Kubernetes control plane configuration AWS What's New ·
- Amazon EKS 1.34+ enables forensic container checkpointing with Kubelet API AWS Containers Blog ·
- Amazon EKS introduces advanced Kubernetes control plane configuration AWS Containers Blog ·