Skip to content

Add Private CA Addon #1020

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 4 commits into from
Jun 4, 2025
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 28 additions & 1 deletion latest/ug/workloads/workloads-add-ons-available-eks.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -78,6 +78,10 @@ You can use any of the following Amazon EKS add-ons.
|<<add-ons-pod-id>>
|EC2, EKS Hybrid Nodes

|Enable users to obtain certificates from AWS Private Certificate Authority (AWS Private CA) for Kubernetes

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Enable cert-manager to issue X.509 certificates from AWS Private CA. Requires cert-manager.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is what we have in the console.

|<<add-ons-aws-privateca-connector>>
|EC2, EKS Auto Mode
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Missing Fargate and Hybrid here


|===

[#add-ons-vpc-cni]
Expand Down Expand Up @@ -483,6 +487,29 @@ eksctl create iamserviceaccount \

For more information, see link:AmazonCloudWatch/latest/monitoring/install-CloudWatch-Observability-EKS-addon.html[Install the CloudWatch agent,type="documentation"].

[#add-ons-aws-privateca-connector]
== AWS Private CA Connector for Kubernetes

[abstract]
--
Learn about the AWS Private CA Connector for Kubernetes Amazon EKS add-on.
--

The AWS Private CA Connector for Kubernetes is an add-on for cert-manager that enables users to obtain Certificates from AWS Private Certificate Authority (AWS Private CA).

* The Amazon EKS add-on name is `aws-privateca-connector-for-kubernetes`.
* The add-on namespace is `aws-privateca-issuer`.

[#add-ons-aws-privateca-connector-iam-permissions]
=== Required IAM permissions

This add-on uses the IAM roles for service accounts capability of Amazon EKS. For more information, see <<iam-roles-for-service-accounts>>.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we support pod identity too.


[#add-ons-aws-privateca-connector-information]
=== Additional information

For more information, see the https://github.com/cert-manager/aws-privateca-issuer[AWS Private CA Issuer for Kubernetes GitHub repository].

[#add-ons-pod-id]
== EKS Pod Identity Agent

Expand All @@ -508,4 +535,4 @@ This add-on users permissions from the <<create-node-role,Amazon EKS node IAM ro
[#add-ons-pod-id-update-information]
=== Update information

You can only update one minor version at a time. For example, if your current version is `1.28.x-eksbuild.y` and you want to update to `1.30.x-eksbuild.y`, then you must update your current version to `1.29.x-eksbuild.y` and then update it again to `1.30.x-eksbuild.y`. For more information about updating the add-on, see <<vpc-add-on-update>>.
You can only update one minor version at a time. For example, if your current version is `1.28.x-eksbuild.y` and you want to update to `1.30.x-eksbuild.y`, then you must update your current version to `1.29.x-eksbuild.y` and then update it again to `1.30.x-eksbuild.y`. For more information about updating the add-on, see <<vpc-add-on-update>>.