Best Practice For Upgrading Amazon EKS Clusters | Rafay

Upgrading Amazon EKS Clusters in 2023

November 29, 2023

Kubernetes is a rapidly evolving open-source project with periodic releases. Organizations embracing Kubernetes must adopt the practice of regular upgrades. Kubernetes has created a versioning and releasing process that follows a quarterly release cycle, typically between 70 and 130 days. The Kubernetes upgrade process is not just limited to the deployed components; one also needs to monitor Kubernetes API versioning. The Kubernetes community has an API versioning scheme with a strict deprecation policy recommending a deprecated GA APIs support period of 12 months or three releases (whichever is longer). Thus, it is necessary to update the cluster and deployed solutions to leverage the latest security features, new functionalities, and bug fixes. Unfortunately, upgrading Kubernetes can be complex as it consists of a collection of components providing various features, from application deployments to logging, monitoring, and persistent data storage.

Kubernetes upgrades are significantly simplified with Amazon EKS, which runs a production-ready version of Kubernetes that ensures optimal cluster performance and functionality. Amazon EKS follows the Kubernetes release philosophy and provides three production-ready versions of Kubernetes concurrently, recommending updates when the latest version becomes available.

How to Update Amazon EKS Clusters Using the AWS Management Console

The EKS upgrade process involves launching new API server nodes with the updated Kubernetes version to replace existing ones. The upgrade process is incremental, so one must adopt all intermediate versions to reach the targeted version. To prepare for an effective Kubernetes upgrade, validate all components that require updates. Test the behavior of applications against new Kubernetes versions before updating production clusters. This article covers the steps involved in incrementally upgrading EKS components.

Prerequisites

First, validate the Kubernetes cluster and worker node versions. The Kubernetes minor version of worker nodes in your cluster must be the same as the version of your control plane:

To get the Kubernetes Control Plane version, use:

$ kubectl version --short

Client Version: v1.19.7
Server Version: v1.18.16-eks-7737de

To determine worker nodes version:

$ kubectl get nodes
NAME                                           STATUS   ROLES    AGE   VERSION
ip-192-168-125-37.us-east-2.compute.internal   Ready    <none>   87m   v1.18.9-eks-d1db3c
ip-192-168-150-29.us-east-2.compute.internal   Ready    <none>   87m   v1.18.9-eks-d1db3c

Amazon EKS clusters come with pod security policies enabled by default. Before updating, ensure that all pod security policies are in place. Validate the default policy with:

$ kubectl get PSP eks.privileged

How to Update the Amazon EKS Control Plane

Amazon EKS allows administrators to upgrade the control plane from the AWS management console. The AWS console shows an information banner with the Update Now button. Click the button to start the upgrade process.

It takes time to update the cluster control plane, during which time the cluster update-history console shows an in-progress task. Conduct this activity during non-peak hours as no changes to the cluster or scheduling nodes can occur while the upgrade is in progress.

Alternatively, the following command can be used to perform an EKS upgrade:

$ docker run --rm -it -v ~/.aws:/root/.aws -v ~/.kube:/root/.kube amazon/aws-cli eks --region us-east-2 update-cluster-version --name dev --kubernetes-version 1.19

The update task returns a task Id that can be referenced for further details.

$ docker run --rm -it -v ~/.aws:/root/.aws -v ~/.kube:/root/.kube amazon/aws-cli eks --region us-east-2 describe-update --name dev --update-id 24938002-69b4-4fbf-a32f-0c1040233144

After the cluster update is complete, the worker nodes need to be updated to the same Kubernetes minor version.

How to Upgrade Amazon EKS Nodes

Scale-down Kubernetes AutoScaler

Kubernetes has a component called "Autoscaler" that ensures every pod has a place to run without leaving nodes idle. Scale down the AutoScaler application to prevent interference during the worker nodes upgrade. Determine the autoscaler using:

$ kubectl get deployment cluster-autoscaler -n kube-system

Update Nodes

The Amazon EKS worker nodes should provide an upgrade message if there’s a possibility of an auto-upgrade. To perform the upgrade, click the update-now button.

Amazon EKS supports a "Rolling Update" strategy to perform a non-disruptive upgrade. This approach deploys a new component version and scales down the older version iteratively. Alternatively, users can select a force update which will stop worker nodes and disrupt executing processes. Choose either strategy to perform upgrades.

It takes time to update the cluster worker nodes during which time the update-history console shows an in-progress task.

Update EKS Addons Nodes

EKS provides managed add-ons for Kube-proxy, CNI VPC, and CoreDNS. The following table lists the recommended add-on versions for supported Kubernetes cluster versions:

Kubernetes Version Kube-proxy CoreDNS VPC CNI
1.20 1.20.4-eksbuild.2 1.8.3 1.8.x
1.19 1.19.6-eksbuild.2 1.8.0 1.8.x
1.18 1.18.8-eksbuild.1 1.7.0 1.8.x
1.17 1.17.9-eksbuild.1 1.6.6 1.8.x

All addons are listed on the EKS cluster addons console. Whenever new versions are available, the respective addon shows an update now button.

Upgrade to the newer version by specifying the version you want to upgrade to. Amazon EKS allows overriding of the existing configuration checkbox to discard the older configuration in favor of the new one.

Streamlining the Amazon EKS Upgrade Process with Rafay

Kubernetes upgrades require effective strategies to keep updated with the latest fixes and features. Rafay provides an automated, standardized process for Amazon EKS upgrades, allowing teams to upgrade their clusters efficiently. Their dashboard shows Upgrade Available notifications and allows for easy selection of components, executing pre and post-upgrade checks to ensure cluster correctness.

Contact Rafay to request your Free Demo today: START FOR FREE