Operations
Upgrade sequence
47 / 69

The order is fixed because each layer depends on the one above it.

Nodes may lag the control plane within the supported skew, but never lead it. Add-ons must support the new version first.

0 Preparedeprecated APIs, PDBs,add-on compatibility,free subnet IPs, backup1 Control planeone minor at a time,AWS does the rolling swap2 Add-onsVPC CNI, CoreDNS, kube-proxy,CSI: update with PRESERVE3 Nodesin place or blue and greenrespect PDBs, drain safely4 VerifySLOs, errors,rollout status,cleanupRules that biteNo downgrades. No skipping minors for the control plane. Nodes never newer than the control plane.Rehearse in a staging cluster built from the same Terraform, and upgrade production clusters in rings.
the sequence in commands
$ aws eks update-cluster-version --name shop-eu --kubernetes-version 1.32
$ aws eks update-addon --cluster-name shop-eu --addon-name vpc-cni --resolve-conflicts PRESERVE
$ aws eks update-nodegroup-version --cluster-name shop-eu --nodegroup-name std