Skip to content

/AWS1/IF_EKS=>ACTIVATECERTIFICATEAUTHORITY()

About ActivateCertificateAuthority

Activates a successor certificate authority (CA) as the signing certificate authority for your cluster, completing a CA rotation.

When you activate a successor CA, Amazon EKS promotes it to be the cluster's signer (its signingStatus becomes IN_USE) and the outgoing CA is retired (NOT_USED). The outgoing CA remains in the cluster's trust bundle but no longer signs certificates. The successor CA you activate must already be present on the cluster and fully distributed (its distributionStatus must be COMPLETE). This is an asynchronous operation that returns an update object you can track with DescribeUpdate .

Before you activate the successor CA, make sure the worker nodes you manage and your external clients have been updated to trust it, so they maintain connectivity to the API server after activation. For a limited period after activation, CA rollback is available to revert to the outgoing CA if needed. If you don't activate the successor CA yourself, Amazon EKS activates it automatically as the expiration deadline approaches. For more information, see Rotate the Amazon EKS cluster certificate authority in the Amazon EKS User Guide.

Method Signature

METHODS /AWS1/IF_EKS~ACTIVATECERTIFICATEAUTHORITY
  IMPORTING
    !IV_CLUSTERNAME TYPE /AWS1/EKSSTRING OPTIONAL
    !IV_CERTIFICATEAUTHORITYID TYPE /AWS1/EKSSTRING OPTIONAL
    !IV_CLIENTREQUESTTOKEN TYPE /AWS1/EKSSTRING OPTIONAL
  RETURNING
    VALUE(OO_OUTPUT) TYPE REF TO /aws1/cl_eksactvtcertauthrsp
  RAISING
    /AWS1/CX_EKSINVALIDPARAMETEREX
    /AWS1/CX_EKSRESOURCENOTFOUNDEX
    /AWS1/CX_EKSSERVEREXCEPTION
    /AWS1/CX_EKSSERVICEUNAVAILEX
    /AWS1/CX_EKSCLIENTEXC
    /AWS1/CX_EKSSERVEREXC
    /AWS1/CX_RT_TECHNICAL_GENERIC
    /AWS1/CX_RT_SERVICE_GENERIC.

IMPORTING

Required arguments:

iv_clustername TYPE /AWS1/EKSSTRING /AWS1/EKSSTRING

The name of your cluster.

iv_certificateauthorityid TYPE /AWS1/EKSSTRING /AWS1/EKSSTRING

The ID of the certificate authority to activate as the cluster's signing certificate authority. This certificate authority must already exist on the cluster and have a distributionStatus of COMPLETE.

Optional arguments:

iv_clientrequesttoken TYPE /AWS1/EKSSTRING /AWS1/EKSSTRING

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

RETURNING

oo_output TYPE REF TO /aws1/cl_eksactvtcertauthrsp /AWS1/CL_EKSACTVTCERTAUTHRSP

Examples

Syntax Example

This is an example of the syntax for calling the method. It includes every possible argument and initializes every possible value. The data provided is not necessarily semantically accurate (for example the value "string" may be provided for something that is intended to be an instance ID, or in some cases two arguments may be mutually exclusive). The syntax shows the ABAP syntax for creating the various data structures.

DATA(lo_result) = lo_client->activatecertificateauthority(
  iv_certificateauthorityid = |string|
  iv_clientrequesttoken = |string|
  iv_clustername = |string|
).

This is an example of reading all possible response values

lo_result = lo_result.
IF lo_result IS NOT INITIAL.
  lo_update = lo_result->get_update( ).
  IF lo_update IS NOT INITIAL.
    lv_string = lo_update->get_id( ).
    lv_updatestatus = lo_update->get_status( ).
    lv_updatetype = lo_update->get_type( ).
    LOOP AT lo_update->get_params( ) into lo_row.
      lo_row_1 = lo_row.
      IF lo_row_1 IS NOT INITIAL.
        lv_updateparamtype = lo_row_1->get_type( ).
        lv_string = lo_row_1->get_value( ).
      ENDIF.
    ENDLOOP.
    lv_timestamp = lo_update->get_createdat( ).
    LOOP AT lo_update->get_errors( ) into lo_row_2.
      lo_row_3 = lo_row_2.
      IF lo_row_3 IS NOT INITIAL.
        lv_errorcode = lo_row_3->get_errorcode( ).
        lv_string = lo_row_3->get_errormessage( ).
        LOOP AT lo_row_3->get_resourceids( ) into lo_row_4.
          lo_row_5 = lo_row_4.
          IF lo_row_5 IS NOT INITIAL.
            lv_string = lo_row_5->get_value( ).
          ENDIF.
        ENDLOOP.
      ENDIF.
    ENDLOOP.
    lo_cancellation = lo_update->get_cancellation( ).
    IF lo_cancellation IS NOT INITIAL.
      lv_cancellationstatus = lo_cancellation->get_status( ).
      lv_string = lo_cancellation->get_reason( ).
    ENDIF.
  ENDIF.
  lo_certificateauthoritysum = lo_result->get_certificateauthority( ).
  IF lo_certificateauthoritysum IS NOT INITIAL.
    lv_string = lo_certificateauthoritysum->get_id( ).
    lv_timestamp = lo_certificateauthoritysum->get_createdat( ).
    lv_certificateauthoritycre = lo_certificateauthoritysum->get_createdby( ).
    lv_timestamp = lo_certificateauthoritysum->get_activatedat( ).
    lv_certificateauthorityact = lo_certificateauthoritysum->get_activatedby( ).
    lv_certificateauthoritysig = lo_certificateauthoritysum->get_signingstatus( ).
    lv_certificateauthoritydis = lo_certificateauthoritysum->get_distributionstatus( ).
  ENDIF.
ENDIF.