Skip to content

/AWS1/IF_EKS=>CREATECERTIFICATEAUTHORITY()

About CreateCertificateAuthority

Appends a successor certificate authority (CA) to your cluster, beginning the CA rotation process.

A cluster certificate authority is the root of trust for your cluster's control plane. It signs the certificates that secure communication between the Kubernetes API server and its clients, and its public certificate is distributed to your cluster's trust bundle so that worker nodes and clients can verify the API server's identity. Each cluster can have at most two certificate authorities at a time: the outgoing CA that's currently signing (its signingStatus is IN_USE) and one successor CA (signingStatus of NOT_USED) that you can later activate to complete the rotation.

Appending a successor CA adds its public certificate to the cluster's trust bundle so that the cluster trusts both CAs simultaneously (the dual trust period), but it doesn't begin signing certificates. Amazon EKS then distributes the successor CA to the Amazon Web Services managed components in your cluster; you can track this through the CA's distributionStatus. The successor CA can't be activated until its distributionStatus is COMPLETE. To activate it as the cluster's signer, use ActivateCertificateAuthority . This is an asynchronous operation that returns an update object. If you don't append a successor CA yourself, Amazon EKS appends one automatically before the outgoing CA approaches expiration.

For more information, see Rotate the Amazon EKS cluster certificate authority in the Amazon EKS User Guide.

Method Signature

METHODS /AWS1/IF_EKS~CREATECERTIFICATEAUTHORITY
  IMPORTING
    !IV_CLUSTERNAME TYPE /AWS1/EKSSTRING OPTIONAL
    !IV_CLIENTREQUESTTOKEN TYPE /AWS1/EKSSTRING OPTIONAL
  RETURNING
    VALUE(OO_OUTPUT) TYPE REF TO /aws1/cl_ekscreatecertauthrsp
  RAISING
    /AWS1/CX_EKSINVALIDPARAMETEREX
    /AWS1/CX_EKSRESOURCEINUSEEX
    /AWS1/CX_EKSRESRCLIMITEXCDEX
    /AWS1/CX_EKSRESOURCENOTFOUNDEX
    /AWS1/CX_EKSSERVEREXCEPTION
    /AWS1/CX_EKSSERVICEUNAVAILEX
    /AWS1/CX_EKSCLIENTEXC
    /AWS1/CX_EKSSERVEREXC
    /AWS1/CX_RT_TECHNICAL_GENERIC
    /AWS1/CX_RT_SERVICE_GENERIC.

IMPORTING

Required arguments:

iv_clustername TYPE /AWS1/EKSSTRING /AWS1/EKSSTRING

The name of your cluster.

Optional arguments:

iv_clientrequesttoken TYPE /AWS1/EKSSTRING /AWS1/EKSSTRING

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

RETURNING

oo_output TYPE REF TO /aws1/cl_ekscreatecertauthrsp /AWS1/CL_EKSCREATECERTAUTHRSP

Examples

Syntax Example

This is an example of the syntax for calling the method. It includes every possible argument and initializes every possible value. The data provided is not necessarily semantically accurate (for example the value "string" may be provided for something that is intended to be an instance ID, or in some cases two arguments may be mutually exclusive). The syntax shows the ABAP syntax for creating the various data structures.

DATA(lo_result) = lo_client->createcertificateauthority(
  iv_clientrequesttoken = |string|
  iv_clustername = |string|
).

This is an example of reading all possible response values

lo_result = lo_result.
IF lo_result IS NOT INITIAL.
  lo_update = lo_result->get_update( ).
  IF lo_update IS NOT INITIAL.
    lv_string = lo_update->get_id( ).
    lv_updatestatus = lo_update->get_status( ).
    lv_updatetype = lo_update->get_type( ).
    LOOP AT lo_update->get_params( ) into lo_row.
      lo_row_1 = lo_row.
      IF lo_row_1 IS NOT INITIAL.
        lv_updateparamtype = lo_row_1->get_type( ).
        lv_string = lo_row_1->get_value( ).
      ENDIF.
    ENDLOOP.
    lv_timestamp = lo_update->get_createdat( ).
    LOOP AT lo_update->get_errors( ) into lo_row_2.
      lo_row_3 = lo_row_2.
      IF lo_row_3 IS NOT INITIAL.
        lv_errorcode = lo_row_3->get_errorcode( ).
        lv_string = lo_row_3->get_errormessage( ).
        LOOP AT lo_row_3->get_resourceids( ) into lo_row_4.
          lo_row_5 = lo_row_4.
          IF lo_row_5 IS NOT INITIAL.
            lv_string = lo_row_5->get_value( ).
          ENDIF.
        ENDLOOP.
      ENDIF.
    ENDLOOP.
    lo_cancellation = lo_update->get_cancellation( ).
    IF lo_cancellation IS NOT INITIAL.
      lv_cancellationstatus = lo_cancellation->get_status( ).
      lv_string = lo_cancellation->get_reason( ).
    ENDIF.
  ENDIF.
  lo_certificateauthoritysum = lo_result->get_certificateauthority( ).
  IF lo_certificateauthoritysum IS NOT INITIAL.
    lv_string = lo_certificateauthoritysum->get_id( ).
    lv_timestamp = lo_certificateauthoritysum->get_createdat( ).
    lv_certificateauthoritycre = lo_certificateauthoritysum->get_createdby( ).
    lv_timestamp = lo_certificateauthoritysum->get_activatedat( ).
    lv_certificateauthorityact = lo_certificateauthoritysum->get_activatedby( ).
    lv_certificateauthoritysig = lo_certificateauthoritysum->get_signingstatus( ).
    lv_certificateauthoritydis = lo_certificateauthoritysum->get_distributionstatus( ).
  ENDIF.
ENDIF.