Skip to content

Deletes a certificate authority (CA) from your cluster

Description

Deletes a certificate authority (CA) from your cluster.

Deleting a certificate authority removes its public certificate from the cluster's trust bundle. You can't delete the certificate authority that's currently signing certificates for the cluster (its signingStatus is IN_USE) — to remove the outgoing CA, first activate the successor CA with activate_certificate_authority . Amazon EKS also protects a successor CA from deletion in certain cases to keep a valid rotation path — for example, a successor that Amazon EKS appended can't be deleted while it's the only successor on the cluster. This is an asynchronous operation that returns an update object.

Usage

eks_delete_certificate_authority(clusterName, certificateAuthorityId,
  clientRequestToken)

Arguments

  • clusterName

    [required] The name of your cluster.

  • certificateAuthorityId

    [required] The ID of the certificate authority to delete. You can't delete the certificate authority that's currently signing certificates for the cluster.

  • clientRequestToken

    A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

Value

A list with the following syntax:

list(
  update = list(
    id = "string",
    status = "InProgress"|"Failed"|"Cancelled"|"Successful",
    type = "VersionUpdate"|"EndpointAccessUpdate"|"LoggingUpdate"|"ConfigUpdate"|"AssociateIdentityProviderConfig"|"DisassociateIdentityProviderConfig"|"AssociateEncryptionConfig"|"AddonUpdate"|"VpcConfigUpdate"|"AccessConfigUpdate"|"UpgradePolicyUpdate"|"ZonalShiftConfigUpdate"|"AutoModeUpdate"|"RemoteNetworkConfigUpdate"|"DeletionProtectionUpdate"|"CapabilityUpdate"|"ControlPlaneScalingConfigUpdate"|"VendedLogsUpdate"|"ControlPlaneEgressUpdate"|"VersionRollback"|"ControlPlaneComponentConfigUpdate"|"CertificateAuthorityUpdate",
    params = list(
      list(
        type = "Version"|"PlatformVersion"|"EndpointPrivateAccess"|"EndpointPublicAccess"|"ClusterLogging"|"DesiredSize"|"LabelsToAdd"|"LabelsToRemove"|"TaintsToAdd"|"TaintsToRemove"|"MaxSize"|"MinSize"|"ReleaseVersion"|"PublicAccessCidrs"|"LaunchTemplateName"|"LaunchTemplateVersion"|"IdentityProviderConfig"|"EncryptionConfig"|"AddonVersion"|"ServiceAccountRoleArn"|"ResolveConflicts"|"MaxUnavailable"|"MaxUnavailablePercentage"|"NodeRepairEnabled"|"UpdateStrategy"|"ConfigurationValues"|"SecurityGroups"|"Subnets"|"AuthenticationMode"|"PodIdentityAssociations"|"UpgradePolicy"|"ZonalShiftConfig"|"ComputeConfig"|"StorageConfig"|"KubernetesNetworkConfig"|"RemoteNetworkConfig"|"DeletionProtection"|"NodeRepairConfig"|"RoleArn"|"RoleMappingsToAddOrUpdate"|"RoleMappingsToRemove"|"NetworkAccess"|"VendedLogs"|"UpdatedTier"|"PreviousTier"|"WarmPoolEnabled"|"WarmPoolMaxGroupPreparedCapacity"|"WarmPoolMinSize"|"WarmPoolState"|"WarmPoolReuseOnScaleIn"|"ControlPlaneEgressMode"|"KubeApiServerConfig"|"KubeSchedulerConfig"|"KubeControllerManagerConfig"|"ActiveCertificateAuthority"|"TrustedCertificateAuthorities"|"CertificateAuthorityId"|"SigningStatus",
        value = "string"
      )
    ),
    createdAt = as.POSIXct(
      "2015-01-01"
    ),
    errors = list(
      list(
        errorCode = "SubnetNotFound"|"SecurityGroupNotFound"|"EniLimitReached"|"IpNotAvailable"|"AccessDenied"|"OperationNotPermitted"|"VpcIdNotFound"|"Unknown"|"NodeCreationFailure"|"PodEvictionFailure"|"InsufficientFreeAddresses"|"ClusterUnreachable"|"InsufficientNumberOfReplicas"|"ConfigurationConflict"|"AdmissionRequestDenied"|"UnsupportedAddonModification"|"K8sResourceNotFound",
        errorMessage = "string",
        resourceIds = list(
          "string"
        )
      )
    ),
    cancellation = list(
      status = "InProgress"|"Failed"|"Successful",
      reason = "string"
    )
  ),
  certificateAuthority = list(
    id = "string",
    createdAt = as.POSIXct(
      "2015-01-01"
    ),
    createdBy = "EKS"|"CUSTOMER",
    activatedAt = as.POSIXct(
      "2015-01-01"
    ),
    activatedBy = "EKS"|"CUSTOMER",
    signingStatus = "NOT_USED"|"ACTIVATING"|"IN_USE",
    distributionStatus = "IN_PROGRESS"|"COMPLETE"|"FAILED"|"DELETING"
  )
)

Request syntax

svc$delete_certificate_authority(
  clusterName = "string",
  certificateAuthorityId = "string",
  clientRequestToken = "string"
)