Treat core components as API-managed add-ons, and always update them with PRESERVE.
AWS tests each add-on version against each supported Kubernetes version and reports health, so updates are a compatibility check, not guesswork.
Conflict resolution on update
PRESERVE
Keeps the field values you customised; only untouched fields change.
OVERWRITE
AWS defaults win. Your custom settings, such as prefix delegation, are silently reverted.
A third value, NONE, leaves existing configuration alone and fails if there is a conflict.
install, configure, update
$ aws eks describe-addon-versions --kubernetes-version 1.31 \ --addon-name vpc-cni --query 'addons[].addonVersions[].addonVersion' $ aws eks update-addon --cluster-name shop-eu --addon-name vpc-cni \ --addon-version v1.19.0-eksbuild.1 --resolve-conflicts PRESERVE \ --configuration-values '{"env":{"ENABLE_PREFIX_DELEGATION":"true"}}' $ aws eks describe-addon --cluster-name shop-eu --addon-name vpc-cni \ --query addon.health