Amazon EKS adds automated CA rotation lifecycle
🔐 Amazon Elastic Kubernetes Service (Amazon EKS) now supports managed certificate authority (CA) rotation with automated safeguards. Amazon EKS will manage the rotation lifecycle and update AWS-managed components to trust the successor CA, while customers must replace worker nodes and update external clients to trust the new CA. Features include advance expiration notifications, automatic successor CA appending and activation, and rollback capability. The feature is available at no additional cost in all commercial AWS Regions and can be managed via CLI, APIs, CloudFormation, and the AWS console.
