shiichan

EKS Cluster Certificates Turn 10 — And Now You Can Actually Rotate Them!

Hey everyone, it's Shiichan! Today's story is about something quiet but important underneath your clusters, let's dig in!

AWS What's New aws.amazon.com

What was announced?

This comes from AWS What's New. Amazon EKS now supports certificate authority (CA) rotation, letting you rotate your cluster's CA through a managed lifecycle with automated safeguards, before it expires.

The story so far

Every EKS cluster has its own CA, which secures encrypted connections to the cluster's Kubernetes API. Clusters created since EKS launched in 2018 have CAs with a 10-year validity period, and those original clusters are now reaching the point where rotation needs to begin. Until now, there wasn't a clear managed way to rotate that CA safely.

What changes

CA rotation is designed as a shared responsibility between AWS and customers.

  • AWS handles: managing the rotation lifecycle, and automatically updating AWS-managed components to trust the successor CA
  • You handle: replacing your worker nodes, and updating external clients that connect to the cluster's API to trust the successor CA

EKS Auto Mode instances and AWS Fargate nodes get updated automatically by AWS, but you're still responsible for updating any external clients that connect to the API server.

Dive Deep

Several automated safeguards help you through the process safely.

  • Advance notifications before the CA expires
  • Automatic appending of a successor CA if you haven't created one yourself
  • Automatic activation if you don't activate on your own schedule
  • A rollback capability to revert to the previous CA if something goes wrong

This is available at no additional cost, in all commercial AWS Regions, and you can manage it through the console, CLI, or CloudFormation. If you're running a cluster that's been around since roughly 2018, it's worth checking your CA's status soon.

Wrap-up

  • EKS cluster CAs can now be rotated through a managed, automated lifecycle
  • AWS updates managed components; you handle worker nodes and external clients
  • EKS Auto Mode and Fargate nodes are updated automatically by AWS
  • Safeguards include advance notice, auto-created successor CAs, auto-activation, and rollback
  • Available in all commercial Regions, at no extra cost

If your cluster has been running since around 2018, now's a good time to check on its CA!