Most failed upgrades were predictable: removed APIs, blocking budgets, incompatible add-ons.
✓Deprecated APIs. Use EKS upgrade insights,
pluto or kubent, and the API server deprecation metric.✓Add-on compatibility. Check the target versions exist for the new Kubernetes version.
✓PodDisruptionBudgets. Ensure at least one Pod can be evicted per workload.
✓Free IPs. The control plane needs a few free addresses in the cluster subnets.
✓Webhooks and CRDs. Controllers, meshes and policy engines support the new version.
✓Backup and rollback plan. Know what you will do if verification fails.
find what will break
$ aws eks list-insights --cluster-name shop-eu \ --filter kubernetesVersions=1.32 $ kubectl get --raw /metrics | \ grep apiserver_requested_deprecated_apis $ pluto detect-helm -o wide --target-versions k8s=v1.32.0 $ kubectl get pdb -A $ aws ec2 describe-subnets --subnet-ids $SUBNETS \ --query 'Subnets[].AvailableIpAddressCount'
Automate these checks in CI so every upgrade ticket starts from a green or a known-red report.