AWS automates EKS certificate authority rotation, ahead of 2018 clusters hitting their 10-year expiry
On August 20, 2026, Amazon EKS announced certificate authority rotation with a managed lifecycle and automated safeguards for every cluster. Clusters created since 2018 are approaching the ten-year validity limit of their CA: rotation is a shared responsibility, and the worker-node and external-client side remains the operator’s job.