Best Practice For Upgrading Amazon EKS Clusters | Rafay

Upgrading Amazon EKS Clusters in 2023

Kubernetes is a rapidly evolving open-source project with periodic releases. Organizations embracing Kubernetes must adopt the practice of regular upgrades because Kubernetes doesn’t follow the Long Term Support (LTS) concept. Instead, they have created a versioning and releasing process that follows a quarterly release cycle, with a cadence ranging between 70 and 130 days. The Kubernetes upgrade process is not just limited to the deployed components; it includes checking Kubernetes API versioning. The Kubernetes community has a strict deprecation policy recommending a deprecated GA APIs support period of 12 months or three releases (whichever is longer). Regularly updating the cluster and deployed solutions leverage the latest security, new features, and bug fixes.

Kubernetes upgrades are significantly simplified with Amazon EKS, which maintains three production-ready versions of Kubernetes at any given time. Support for new Kubernetes GA versions is provided sometime after release, and Amazon EKS recommends updating your cluster to the latest version when available.

How to Update Amazon EKS Clusters Using the AWS Management Console

The Amazon EKS upgrade process involves launching new API server nodes with the updated Kubernetes version to replace the existing ones. The upgrade process is incremental and does not allow jumping to the latest version directly.

To prepare for an effective Kubernetes upgrade, you must determine all components, along with the control plane, that require an update. It’s best practice to test your apps against new versions of Kubernetes before updating your production clusters. This article covers the steps involved in incrementally upgrading EKS components.

Prerequisites

Validate the version of your Kubernetes cluster and worker nodes. The Kubernetes minor version of worker nodes must match the control plane’s current version. You can get the Kubernetes Control Plane using:
$ kubectl version --short
Output:
Client Version: v1.19.7 Server Version: v1.18.16-eks-7737de
Determine the worker nodes version using:
$ kubectl get nodes

NAME                                           STATUS   ROLES    AGE   VERSION
ip-192-168-125-37.us-east-2.compute.internal   Ready    <none>   87m   v1.18.9-eks-d1db3c
ip-192-168-150-29.us-east-2.compute.internal   Ready    <none>   87m   v1.18.9-eks-d1db3c

Amazon EKS clusters come with a pod security policy admission controller enabled by default. Validate the default policy with:
$ kubectl get PSP eks.privileged

How to Update the Amazon EKS Control Plane

Amazon EKS allows upgrading the control plane from the AWS management console. The console provides an information banner with the "Update Now" button to start the upgrade process.

During the update, the cluster update-history console shows an in-progress task regarding the upgrade. Conduct this activity during non-peak hours, as changes to the cluster or scheduling nodes are not permitted while the upgrade is in progress.

You can also use the CLI commands for an Amazon EKS upgrade:
$ docker run --rm -it -v ~/.aws:/root/.aws -v ~/.kube:/root/.kube amazon/aws-cli eks --region us-east-2 update-cluster-version --name dev --kubernetes-version 1.19

Once the cluster update is complete, update your worker nodes to the same Kubernetes minor version.

How to Upgrade Amazon EKS Nodes

Scale-down Kubernetes AutoScaler

The Kubernetes Autoscaler ensures that every pod has a place to run and no nodes are left idle, so scaling down the AutoScaler application is imperative during worker nodes upgrade. Determine the autoscaler using:
$ kubectl get deployment cluster-autoscaler -n kube-system

Update Nodes

The Amazon EKS worker nodes may provide an upgrade message if an auto-upgrade is possible. Click the "update-now" button to perform the upgrade.

Kubernetes nodes are responsible for executing workloads. Amazon EKS utilizes a “Rolling Update” strategy for a non-disruptive upgrade, deploying a new component version and scaling down the old version until replaced.

Update EKS Addon Nodes

Amazon EKS provides managed add-ons for Kube-proxy, CNI VPC, and CoreDNS. The following table lists EKS recommended add-on versions for each supported Kubernetes version:

Kubernetes version 1.20 1.19 1.18 1.17
kube-proxy 1.20.4-eksbuild.2 1.19.6-eksbuild.2 1.18.8-eksbuild.1 1.17.9-eksbuild.1
CoreDNS 1.8.3 1.8.0 1.7.0 1.6.6
VPC CNI 1.8.x 1.8.x 1.8.x 1.8.x

All addons are listed on the EKS cluster addons console. Whenever a new addon version is available, the respective addon will show an update now button.

Upgrade to the newest version by specifying the addon version you want to upgrade.

Update Kubeproxy

Specify the version of the addon to run.

Update the Cluster DNS Provider

Upgrade the cluster DNS provider to the latest supported version by specifying the addon version.

Update VPC CNI

Amazon EKS add-ons support AWS IAM roles for service accounts that allow permissions inheritance from the EC2 nodes where they are installed. Check and upgrade the version of the cluster’s Amazon VPC CNI Plugin for Kubernetes.

Rafay’s Automated Amazon EKS Upgrade Process

Organizations often have multiple EKS clusters across different environments, leading to repetitive manual upgrade steps that are time-consuming. Rafay provides an automated, standardized, and repeatable process for Amazon EKS upgrades.

The console allows selection of components for upgrade, including control planes, worker node groups, and cluster add-ons, handling the entire process and conducting pre and post-upgrade checks for cluster correctness.

The cog icon for cluster actions provides an “upgrade cluster” action item. Click the action menu or the info message to start a Kubernetes Version upgrade.

You can select the Control Plane + Node groups option to initiate the upgrade. Rafay keeps a detailed record of all applied upgrades for auditing and governance needs. After submitting the upgrade job, Rafay performs pre-checks, executes the upgrade, and conducts post-upgrade validation checks.

Streamlining the Amazon EKS Upgrade Process with Rafay

Kubernetes adopters need an effective upgrade strategy to keep updated with the latest fixes and take advantage of new features. This article presents the steps to upgrade Amazon EKS clusters using the AWS Management console. Amazon EKS addresses many operational challenges for cluster upgrades, allowing you to focus on workloads and business value over control plane high availability or data plane compatibility.

Rafay's automation tools simplify the process of upgrading Amazon EKS clusters, enabling a repeatable, consistent, and automated EKS upgrade process that boosts team productivity and leverages the latest Kubernetes features. Contact Rafay and request your Free Demo today: START FOR FREE

Tags:
Amazon
Amazon EKS
Amazon Elastic Kubernetes Service
AWS
EKS Upgrades
K8s
K8s Upgrades
Upgrade Kubernetes