[EKS] [request]: Allow AssociateEncryptionConfig to be removed or rolled back
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
### Community Note
* Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
* If you are interested in working on this issue or have submitted a pull request, please leave a comment
**Tell us about your request**
What do you want us to build? When AssociateEncryptionConfig is run against a cluster, there is no way to revert this change. This request is to add the ability to remove encryption from a cluster.
**Which service(s) is this request for?**
EKS
**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
What outcome are you trying to achieve, ultimately, and why is it hard/impossible to do right now? What is the impact of not having this problem solved? The more details you can provide, the better we'll be able to understand and solve the problem.
The issue is that, once encryption is applied there is no way to remove it. This means, even in testing, if encryption is potentially causing an issue, the only way to remove encryption is to create a new cluster, which also requires recreating all other components. Adding this feature would make testing and rolling back within a single cluster possible.
**Are you currently working around this issue?**
How are you currently solving this problem?
Create a new cluster.
**Additional context**
Anything else we should know?
**Attachments**
If you think you might have additional information that you'd like to include via an attachment, please do - we'll take a look. (Remember to remove any personally-identifiable information.)
Contributor guide
Research direction
The request concerns the EKS AssociateEncryptionConfig operation and asks for encryption removal or rollback, but it names no repository files, tests, or implementation entry points. Start by reviewing the EKS operation's behavior and constraints; done means establishing whether a cluster's encryption can be removed or reverted without recreating the cluster.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, kubernetes
- Domain
- cloud, infrastructure
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100