Home icon

Amazon EKS now supports certificate authority (CA) rotation with automated lifecycle management

News



This article announces certificate authority (CA) rotation support in Amazon EKS, enabling customers to rotate their cluster's CA through a managed lifecycle with automated safeguards.

  • EKS clusters from 2018 have 10-year CA validity and now need rotation before expiration
  • AWS manages rotation lifecycle and updates AWS-managed components; customers update worker nodes and external clients
  • EKS Auto Mode and Fargate nodes updated automatically by AWS
  • Automated safeguards include advance notifications, automatic successor CA creation, and rollback capability
  • Available at no additional cost in all commercial AWS Regions via CLI, APIs, CloudFormation, and console

CA rotation ensures Amazon EKS clusters remain operational and secure as certificates approach expiration.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Aug 19
2026
Deep dive into Amazon EKS certificate authority rotation
Aug 12
2026
Amazon EKS now supports advanced Kubernetes control plane configuration parameters
Aug 21
2026
Amazon EKS Capability for Argo CD now supports custom configuration
Aug 24
2026
Amazon EKS now supports multiple external OIDC identity providers per cluster

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.