Skip to content

Activates a successor certificate authority (CA) as the signing certificate authority for your cluster, completing a CA rotation

Description

Activates a successor certificate authority (CA) as the signing certificate authority for your cluster, completing a CA rotation.

When you activate a successor CA, Amazon EKS promotes it to be the cluster's signer (its signingStatus becomes IN_USE) and the outgoing CA is retired (NOT_USED). The outgoing CA remains in the cluster's trust bundle but no longer signs certificates. The successor CA you activate must already be present on the cluster and fully distributed (its distributionStatus must be COMPLETE). This is an asynchronous operation that returns an update object you can track with describe_update .

Before you activate the successor CA, make sure the worker nodes you manage and your external clients have been updated to trust it, so they maintain connectivity to the API server after activation. For a limited period after activation, CA rollback is available to revert to the outgoing CA if needed. If you don't activate the successor CA yourself, Amazon EKS activates it automatically as the expiration deadline approaches. For more information, see Rotate the Amazon EKS cluster certificate authority in the Amazon EKS User Guide.

Usage

eks_activate_certificate_authority(clusterName, certificateAuthorityId,
  clientRequestToken)

Arguments

  • clusterName

    [required] The name of your cluster.

  • certificateAuthorityId

    [required] The ID of the certificate authority to activate as the cluster's signing certificate authority. This certificate authority must already exist on the cluster and have a distributionStatus of COMPLETE.

  • clientRequestToken

    A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

Value

A list with the following syntax:

list(
  update = list(
    id = "string",
    status = "InProgress"|"Failed"|"Cancelled"|"Successful",
    type = "VersionUpdate"|"EndpointAccessUpdate"|"LoggingUpdate"|"ConfigUpdate"|"AssociateIdentityProviderConfig"|"DisassociateIdentityProviderConfig"|"AssociateEncryptionConfig"|"AddonUpdate"|"VpcConfigUpdate"|"AccessConfigUpdate"|"UpgradePolicyUpdate"|"ZonalShiftConfigUpdate"|"AutoModeUpdate"|"RemoteNetworkConfigUpdate"|"DeletionProtectionUpdate"|"CapabilityUpdate"|"ControlPlaneScalingConfigUpdate"|"VendedLogsUpdate"|"ControlPlaneEgressUpdate"|"VersionRollback"|"ControlPlaneComponentConfigUpdate"|"CertificateAuthorityUpdate",
    params = list(
      list(
        type = "Version"|"PlatformVersion"|"EndpointPrivateAccess"|"EndpointPublicAccess"|"ClusterLogging"|"DesiredSize"|"LabelsToAdd"|"LabelsToRemove"|"TaintsToAdd"|"TaintsToRemove"|"MaxSize"|"MinSize"|"ReleaseVersion"|"PublicAccessCidrs"|"LaunchTemplateName"|"LaunchTemplateVersion"|"IdentityProviderConfig"|"EncryptionConfig"|"AddonVersion"|"ServiceAccountRoleArn"|"ResolveConflicts"|"MaxUnavailable"|"MaxUnavailablePercentage"|"NodeRepairEnabled"|"UpdateStrategy"|"ConfigurationValues"|"SecurityGroups"|"Subnets"|"AuthenticationMode"|"PodIdentityAssociations"|"UpgradePolicy"|"ZonalShiftConfig"|"ComputeConfig"|"StorageConfig"|"KubernetesNetworkConfig"|"RemoteNetworkConfig"|"DeletionProtection"|"NodeRepairConfig"|"RoleArn"|"RoleMappingsToAddOrUpdate"|"RoleMappingsToRemove"|"NetworkAccess"|"VendedLogs"|"UpdatedTier"|"PreviousTier"|"WarmPoolEnabled"|"WarmPoolMaxGroupPreparedCapacity"|"WarmPoolMinSize"|"WarmPoolState"|"WarmPoolReuseOnScaleIn"|"ControlPlaneEgressMode"|"KubeApiServerConfig"|"KubeSchedulerConfig"|"KubeControllerManagerConfig"|"ActiveCertificateAuthority"|"TrustedCertificateAuthorities"|"CertificateAuthorityId"|"SigningStatus",
        value = "string"
      )
    ),
    createdAt = as.POSIXct(
      "2015-01-01"
    ),
    errors = list(
      list(
        errorCode = "SubnetNotFound"|"SecurityGroupNotFound"|"EniLimitReached"|"IpNotAvailable"|"AccessDenied"|"OperationNotPermitted"|"VpcIdNotFound"|"Unknown"|"NodeCreationFailure"|"PodEvictionFailure"|"InsufficientFreeAddresses"|"ClusterUnreachable"|"InsufficientNumberOfReplicas"|"ConfigurationConflict"|"AdmissionRequestDenied"|"UnsupportedAddonModification"|"K8sResourceNotFound",
        errorMessage = "string",
        resourceIds = list(
          "string"
        )
      )
    ),
    cancellation = list(
      status = "InProgress"|"Failed"|"Successful",
      reason = "string"
    )
  ),
  certificateAuthority = list(
    id = "string",
    createdAt = as.POSIXct(
      "2015-01-01"
    ),
    createdBy = "EKS"|"CUSTOMER",
    activatedAt = as.POSIXct(
      "2015-01-01"
    ),
    activatedBy = "EKS"|"CUSTOMER",
    signingStatus = "NOT_USED"|"ACTIVATING"|"IN_USE",
    distributionStatus = "IN_PROGRESS"|"COMPLETE"|"FAILED"|"DELETING"
  )
)

Request syntax

svc$activate_certificate_authority(
  clusterName = "string",
  certificateAuthorityId = "string",
  clientRequestToken = "string"
)