Appends a successor certificate authority (CA) to your cluster, beginning the CA rotation process.
A cluster certificate authority is the root of trust for your cluster's control plane. It signs the certificates that secure communication between the Kubernetes API server and its clients, and its public certificate is distributed to your cluster's trust bundle so that worker nodes and clients can verify the API server's identity. Each cluster can have at most two certificate authorities at a time: the outgoing CA that's currently signing (its
signingStatus is
IN_USE) and one successor CA (
signingStatus of
NOT_USED) that you can later activate to complete the rotation.
Appending a successor CA adds its public certificate to the cluster's trust bundle so that the cluster trusts both CAs simultaneously (the dual trust period), but it doesn't begin signing certificates. Amazon EKS then distributes the successor CA to the Amazon Web Services managed components in your cluster; you can track this through the CA's
distributionStatus. The successor CA can't be activated until its
distributionStatus is
COMPLETE. To activate it as the cluster's signer, use
ActivateCertificateAuthority. This is an asynchronous operation that returns an
update object. If you don't append a successor CA yourself, Amazon EKS appends one automatically before the outgoing CA approaches expiration.
For more information, see
Rotate the Amazon EKS cluster certificate authority in the
Amazon EKS User Guide.