- Introduces automated certificate authority (CA) rotation for Amazon EKS clusters, enabling proactive replacement before expiration.
- Provides safeguards such as advance notifications, automatic successor CA appending, activation, and rollback, while requiring customers to update worker nodes and external clients.
- Feature is available at no additional cost and can be managed via AWS CLI, EKS APIs, CloudFormation, or the console.