Skip to content

Appends a successor certificate authority (CA) to your cluster, beginning the CA rotation process

Description

Appends a successor certificate authority (CA) to your cluster, beginning the CA rotation process.

A cluster certificate authority is the root of trust for your cluster's control plane. It signs the certificates that secure communication between the Kubernetes API server and its clients, and its public certificate is distributed to your cluster's trust bundle so that worker nodes and clients can verify the API server's identity. Each cluster can have at most two certificate authorities at a time: the outgoing CA that's currently signing (its signingStatus is IN_USE) and one successor CA (signingStatus of NOT_USED) that you can later activate to complete the rotation.

Appending a successor CA adds its public certificate to the cluster's trust bundle so that the cluster trusts both CAs simultaneously (the dual trust period), but it doesn't begin signing certificates. Amazon EKS then distributes the successor CA to the Amazon Web Services managed components in your cluster; you can track this through the CA's distributionStatus. The successor CA can't be activated until its distributionStatus is COMPLETE. To activate it as the cluster's signer, use activate_certificate_authority . This is an asynchronous operation that returns an update object. If you don't append a successor CA yourself, Amazon EKS appends one automatically before the outgoing CA approaches expiration.

For more information, see Rotate the Amazon EKS cluster certificate authority in the Amazon EKS User Guide.

Usage

eks_create_certificate_authority(clusterName, clientRequestToken)

Arguments

  • clusterName

    [required] The name of your cluster.

  • clientRequestToken

    A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

Value

A list with the following syntax:

list(
  update = list(
    id = "string",
    status = "InProgress"|"Failed"|"Cancelled"|"Successful",
    type = "VersionUpdate"|"EndpointAccessUpdate"|"LoggingUpdate"|"ConfigUpdate"|"AssociateIdentityProviderConfig"|"DisassociateIdentityProviderConfig"|"AssociateEncryptionConfig"|"AddonUpdate"|"VpcConfigUpdate"|"AccessConfigUpdate"|"UpgradePolicyUpdate"|"ZonalShiftConfigUpdate"|"AutoModeUpdate"|"RemoteNetworkConfigUpdate"|"DeletionProtectionUpdate"|"CapabilityUpdate"|"ControlPlaneScalingConfigUpdate"|"VendedLogsUpdate"|"ControlPlaneEgressUpdate"|"VersionRollback"|"ControlPlaneComponentConfigUpdate"|"CertificateAuthorityUpdate",
    params = list(
      list(
        type = "Version"|"PlatformVersion"|"EndpointPrivateAccess"|"EndpointPublicAccess"|"ClusterLogging"|"DesiredSize"|"LabelsToAdd"|"LabelsToRemove"|"TaintsToAdd"|"TaintsToRemove"|"MaxSize"|"MinSize"|"ReleaseVersion"|"PublicAccessCidrs"|"LaunchTemplateName"|"LaunchTemplateVersion"|"IdentityProviderConfig"|"EncryptionConfig"|"AddonVersion"|"ServiceAccountRoleArn"|"ResolveConflicts"|"MaxUnavailable"|"MaxUnavailablePercentage"|"NodeRepairEnabled"|"UpdateStrategy"|"ConfigurationValues"|"SecurityGroups"|"Subnets"|"AuthenticationMode"|"PodIdentityAssociations"|"UpgradePolicy"|"ZonalShiftConfig"|"ComputeConfig"|"StorageConfig"|"KubernetesNetworkConfig"|"RemoteNetworkConfig"|"DeletionProtection"|"NodeRepairConfig"|"RoleArn"|"RoleMappingsToAddOrUpdate"|"RoleMappingsToRemove"|"NetworkAccess"|"VendedLogs"|"UpdatedTier"|"PreviousTier"|"WarmPoolEnabled"|"WarmPoolMaxGroupPreparedCapacity"|"WarmPoolMinSize"|"WarmPoolState"|"WarmPoolReuseOnScaleIn"|"ControlPlaneEgressMode"|"KubeApiServerConfig"|"KubeSchedulerConfig"|"KubeControllerManagerConfig"|"ActiveCertificateAuthority"|"TrustedCertificateAuthorities"|"CertificateAuthorityId"|"SigningStatus",
        value = "string"
      )
    ),
    createdAt = as.POSIXct(
      "2015-01-01"
    ),
    errors = list(
      list(
        errorCode = "SubnetNotFound"|"SecurityGroupNotFound"|"EniLimitReached"|"IpNotAvailable"|"AccessDenied"|"OperationNotPermitted"|"VpcIdNotFound"|"Unknown"|"NodeCreationFailure"|"PodEvictionFailure"|"InsufficientFreeAddresses"|"ClusterUnreachable"|"InsufficientNumberOfReplicas"|"ConfigurationConflict"|"AdmissionRequestDenied"|"UnsupportedAddonModification"|"K8sResourceNotFound",
        errorMessage = "string",
        resourceIds = list(
          "string"
        )
      )
    ),
    cancellation = list(
      status = "InProgress"|"Failed"|"Successful",
      reason = "string"
    )
  ),
  certificateAuthority = list(
    id = "string",
    createdAt = as.POSIXct(
      "2015-01-01"
    ),
    createdBy = "EKS"|"CUSTOMER",
    activatedAt = as.POSIXct(
      "2015-01-01"
    ),
    activatedBy = "EKS"|"CUSTOMER",
    signingStatus = "NOT_USED"|"ACTIVATING"|"IN_USE",
    distributionStatus = "IN_PROGRESS"|"COMPLETE"|"FAILED"|"DELETING"
  )
)

Request syntax

svc$create_certificate_authority(
  clusterName = "string",
  clientRequestToken = "string"
)