Operations
Pre-upgrade checks
49 / 69

Most failed upgrades were predictable: removed APIs, blocking budgets, incompatible add-ons.

✓Deprecated APIs. Use EKS upgrade insights, pluto or kubent, and the API server deprecation metric.
✓Add-on compatibility. Check the target versions exist for the new Kubernetes version.
✓PodDisruptionBudgets. Ensure at least one Pod can be evicted per workload.
✓Free IPs. The control plane needs a few free addresses in the cluster subnets.
✓Webhooks and CRDs. Controllers, meshes and policy engines support the new version.
✓Backup and rollback plan. Know what you will do if verification fails.
find what will break
$ aws eks list-insights --cluster-name shop-eu \
    --filter kubernetesVersions=1.32
$ kubectl get --raw /metrics | \
    grep apiserver_requested_deprecated_apis
$ pluto detect-helm -o wide --target-versions k8s=v1.32.0
$ kubectl get pdb -A
$ aws ec2 describe-subnets --subnet-ids $SUBNETS \
    --query 'Subnets[].AvailableIpAddressCount'

Automate these checks in CI so every upgrade ticket starts from a green or a known-red report.