OFICIAL AWS What's New

Amazon EKS now supports certificate authority (CA) rotation with automated lifecycle management

What happened
Based on AWS What's New · Aug 20, 2026

Amazon EKS now offers automated certificate authority (CA) rotation with lifecycle management to maintain secure cluster operations as original CAs near expiration.

Amazon EKS now supports certificate authority (CA) rotation with automated lifecycle management
AWS What's New — Amazon Web Services
Key points
·
Today, Amazon Elastic Kubernetes Service (Amazon EKS) details certificate authority (CA) rotation, enabling customers to rotate their cluster's CA through a managed lifecycle with automated safeguards.
·
Each Amazon EKS cluster has its own CA that allows encrypted connections to the cluster's Kubernetes API, and now you can rotate the CA before it expires to ensure your cluster remains operational and secure.
·
Amazon EKS clusters created since launch in 2018 have CAs with a 10-year validity period, and clusters from that era are now approaching the point where CA rotation activities should begin.
·
Amazon EKS manages the rotation lifecycle and automatically updates AWS-managed components to trust the successor CA.
Key numbers
·
Clusters created since 2018 have CAs valid for 10 years, prompting the need for rotation as these certificates approach expiration.

Amazon Elastic Kubernetes Service (EKS) has introduced certificate authority (CA) rotation, allowing customers to automate the renewal of cluster CAs before they expire. This feature ensures uninterrupted and secure access to the Kubernetes API server, which relies on encrypted connections. Clusters created since 2018 have CAs valid for 10 years, prompting the need for rotation as these certificates approach expiration. The process is managed through a shared responsibility model between AWS and customers.

Customers are responsible for updating worker nodes and external clients to trust the new CA, while AWS handles updates for EKS Auto Mode instances and AWS Fargate nodes. Amazon EKS provides automated safeguards, including advance notifications, automatic successor CA creation, and activation if the customer does not act. A rollback feature is also available to revert to the previous CA if issues arise during the transition.

The CA rotation feature is available at no additional cost across all commercial AWS Regions. Customers can initiate rotation using AWS CLI, EKS APIs, CloudFormation, or the AWS Management Console. This update addresses the growing need for automated certificate management as clusters age.

For detailed guidance, AWS offers documentation and a deep dive on CA rotation in Amazon EKS. The feature aims to simplify certificate lifecycle management while maintaining security and operational continuity for Kubernetes clusters.

Original source → Deals on Clipraptor.com →