Amazon EKS now supports certificate authority (CA) rotation with automated lifecycle management
News
This article announces certificate authority (CA) rotation support in Amazon EKS, enabling customers to rotate their cluster's CA through a managed lifecycle with automated safeguards.
- EKS clusters from 2018 have 10-year CA validity and now need rotation before expiration
- AWS manages rotation lifecycle and updates AWS-managed components; customers update worker nodes and external clients
- EKS Auto Mode and Fargate nodes updated automatically by AWS
- Automated safeguards include advance notifications, automatic successor CA creation, and rollback capability
- Available at no additional cost in all commercial AWS Regions via CLI, APIs, CloudFormation, and console
CA rotation ensures Amazon EKS clusters remain operational and secure as certificates approach expiration.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Aug 19
2026
2026
Deep dive into Amazon EKS certificate authority rotation
Aug 12
2026
2026
Amazon EKS now supports advanced Kubernetes control plane configuration parameters
Aug 21
2026
2026
Amazon EKS Capability for Argo CD now supports custom configuration
Aug 24
2026
2026
Amazon EKS now supports multiple external OIDC identity providers per cluster
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.