{"slug":"eks-upgrade-readiness","title":"eks-upgrade-readiness","summary":"Use this skill when a user asks to assess, plan, or validate an","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-09-17T16:54:18.252502Z","repo":{"url":"https://github.com/aws/tools-for-devops-agent","stars":82,"forks":62,"license":"Apache-2.0","updatedAt":"2026-09-25T14:34:10Z"},"bodyHtml":"<h1>EKS Upgrade Readiness Skill</h1>\n<p>A skill for AWS DevOps Agent that performs <strong>read-only</strong> upgrade readiness\nassessments for Amazon EKS clusters, aligned with the\n<a href=\"https://docs.aws.amazon.com/eks/latest/best-practices/cluster-upgrades.html\">AWS EKS Best Practices Guide — Cluster Upgrades</a>.</p>\n<h2>Purpose</h2>\n<p>EKS upgrades can fail or cause downtime when deprecated APIs, incompatible\naddons, version-skewed node groups, or misconfigured PDBs are not caught\nbeforehand. This skill systematically checks every dimension the Best Practices\nGuide calls out and produces a READY / NOT READY / READY WITH WARNINGS /\nCANNOT DETERMINE verdict with a prioritized remediation plan.</p>\n<h2>Key Capabilities</h2>\n<ul>\n<li><strong>EKS Upgrade Insights (primary signal)</strong> — UPGRADE_READINESS findings from\nthe ListInsights/DescribeInsight APIs</li>\n<li><strong>Infrastructure prerequisites</strong> — subnet IP availability (VPC CNI mode-aware),\nIAM role, KMS key, service quotas</li>\n<li><strong>API deprecation analysis</strong> — maps removed APIs to replacements, scans Helm\nstored manifests (deployed revision), vendor-aware CRD checks</li>\n<li><strong>Addon compatibility (live API)</strong> — validates managed addons via\nDescribeAddonVersions, detects self-managed addons via deployment/Helm scan</li>\n<li><strong>Full data plane inventory</strong> — managed node groups, self-managed ASGs,\nKarpenter (Drift, expiry, EC2NodeClass, budgets), Auto Mode, Fargate profiles,\nkubelet version map</li>\n<li><strong>AL2→AL2023 migration</strong> — launch template analysis, custom AMI detection,\nbootstrap differences, cgroup v2, IMDSv2</li>\n<li><strong>Upgrade ordering</strong> — pre-upgrade alignment (Karpenter/CA/webhooks before CP)\nvs post-upgrade sequence</li>\n<li><strong>PDB and topology spread</strong> — detects drain blockers and availability risks</li>\n<li><strong>StatefulSet safety</strong> — grace period, PVC retention policy, single-replica risks</li>\n<li><strong>Pre-upgrade health baseline</strong> — node Ready status, pending CSRs, system pod\nhealth, DNS/metrics baseline</li>\n<li><strong>Capacity planning</strong> — surge calculation, ODCR/FDCR guidance, blue-green\nalternative, autoscaler pause</li>\n<li><strong>GitOps/IaC detection</strong> — routes remediation through owning tool\n(Terraform/CDK/ArgoCD/Flux/eksctl)</li>\n<li><strong>Post-upgrade validation</strong> — DNS, metrics, scheduling, LB health, IRSA smoke tests</li>\n<li><strong>Client/CI tooling skew</strong> — kubectl (±1 minor), eksctl, Helm, Terraform provider checks (WARN-level)</li>\n<li><strong>Pod Identity awareness</strong> — addon version check plus IRSA-vs-Pod-Identity blue-green migration guidance</li>\n<li><strong>Remediation playbook</strong> — all mutations separated, require operator approval</li>\n<li><strong>Structured upgrade plan</strong> — ordered execution with rollback gates</li>\n<li><strong>Machine-readable output</strong> — optional JSON verdict (per-gate status, confidence,\nevidence) alongside the markdown report, for CI/CD gating</li>\n</ul>\n<h2>Prerequisites</h2>\n<h3>IAM Permissions</h3>\n<p>The DevOps Agent role needs read access to EKS, EC2, IAM, and Auto Scaling:</p>\n<pre><code>eks:DescribeCluster\neks:ListClusters\neks:ListInsights\neks:DescribeInsight\neks:ListAddons\neks:DescribeAddon\neks:DescribeAddonVersions\neks:ListNodegroups\neks:DescribeNodegroup\neks:ListFargateProfiles\neks:DescribeFargateProfile\neks:ListUpdates\neks:DescribeUpdate\nec2:DescribeSubnets\nec2:DescribeInstances\nec2:DescribeLaunchTemplateVersions\nec2:DescribeImages\nec2:DescribeCapacityReservations\niam:GetRole\nautoscaling:DescribeAutoScalingGroups\nautoscaling:DescribeLaunchConfigurations\nservicequotas:GetServiceQuota\n</code></pre>\n<h3>Kubernetes RBAC (if kubectl access available)</h3>\n<p>A <code>ClusterRole</code> with read-only access to nodes, pods, deployments, statefulsets,\ndaemonsets, PDBs, configmaps, secrets (Helm), CRDs, CSRs, Karpenter resources,\nand ENIConfigs. See the \"Required Permissions\" section in SKILL.md for the\nfull <code>ClusterRole</code> manifest. <code>kubectl</code> access is optional — the assessment\nstill runs on AWS APIs alone at lower confidence for CRD/Helm/PDB checks.</p>\n<h3>AWS Resources</h3>\n<ul>\n<li>One or more Amazon EKS clusters (any supported version)</li>\n<li>Control plane logging enabled (recommended for post-upgrade debugging)</li>\n</ul>\n<h2>Limitations</h2>\n<ul>\n<li><strong>EKS clusters only.</strong> Does not cover EKS Anywhere, Outposts, or Local Zones.</li>\n<li><strong>Read-only by design.</strong> The skill produces recommendations; it never executes\nmutating APIs. All mutations are in the Remediation Playbook (Step 14).</li>\n<li><strong>UNKNOWN ≠ PASS.</strong> Missing data or access denial produces UNKNOWN, never\nPASS. The overall verdict cannot be READY while any gate is UNKNOWN.</li>\n<li><strong>Addon version data may lag.</strong> Static reference table is fallback only —\nalways prefer live <code>describe-addon-versions</code> API.</li>\n<li><strong>Pagination required.</strong> Large clusters with many node groups or addons\nrequire exhausting API pagination tokens.</li>\n</ul>\n<h2>Agent Types</h2>\n<ul>\n<li><strong>Chat tasks</strong> — ask for upgrade readiness assessments</li>\n<li><strong>Evaluation</strong> — periodic upgrade readiness scans</li>\n</ul>\n<h2>Uploading to AWS DevOps Agent</h2>\n<p><strong>Option A: Import from GitHub (recommended)</strong></p>\n<p>If you have a <a href=\"https://docs.aws.amazon.com/devopsagent/latest/userguide/connecting-to-cicd-pipelines-connecting-github.html\">GitHub connection configured</a> in your Agent Space, you can import this skill directly from the repository. In the DevOps Agent web app, go to Settings → Add Skill → Import from repository, then\npoint to <code>skills/eks-upgrade-readiness</code>. See <a href=\"https://docs.aws.amazon.com/devopsagent/latest/userguide/about-aws-devops-agent-devops-agent-skills.html#creating-skills\">Importing a skill from a repository</a> for full instructions.</p>\n<blockquote>\n<p><strong>Note:</strong> You cannot connect the <code>aws-samples</code> GitHub organization directly because the GitHub connection setup requires admin rights on the organization. Instead, connect your personal GitHub account and select any repository from it during the connection setup. Once a GitHub connection is established, you can import skills from any public repository, including this one, even if it wasn't selected during the connection setup.</p>\n</blockquote>\n<p><strong>Option B: Upload as a zip file</strong></p>\n<ol>\n<li>Zip the <code>eks-upgrade-readiness/</code> directory (only including allowed extensions):</li>\n</ol>\n<pre><code>cd skills\nzip -r eks-upgrade-readiness.zip eks-upgrade-readiness/ \\\n  -i '*.md' '*.json' '*.yaml' '*.yml' \\\n  -x '*/README.md' '*/.skilleval.yaml' '*/CHANGELOG.md' '*/evals/*'\n</code></pre>\n<ol start=\"2\">\n<li>In the AWS DevOps Agent web app, navigate to the <strong>Skills</strong> page.</li>\n<li>Click <strong>Add skill</strong> → <strong>Upload skill</strong>.</li>\n<li>Drag and drop the <code>eks-upgrade-readiness.zip</code> file (max 6 MB).</li>\n<li>Select the agent types: <strong>Chat tasks</strong> and <strong>Evaluation</strong>.</li>\n<li>Click <strong>Upload</strong>.</li>\n</ol>\n<p><strong>Option C: Upload via the Asset API</strong></p>\n<p>Use the DevOps Agent Asset API to programmatically manage skills — useful for CI/CD pipelines or automation workflows. Assign to <code>CHAT</code> and <code>EVALUATION</code> agent types. See <a href=\"https://docs.aws.amazon.com/devopsagent/latest/userguide/about-aws-devops-agent-managing-assets.html#managing-a-skill-end-to-end\">Managing a skill end-to-end</a> for the full API workflow.</p>\n<h2>How to Use This Skill</h2>\n<p>Describe the task in natural language — you do not need to name the skill.</p>\n<h3>Example Prompts</h3>\n<pre><code>\"Is my EKS cluster prod-cluster in us-east-1 ready to upgrade to 1.31?\"\n\"Check upgrade readiness for all my EKS clusters\"\n\"What deprecated APIs would break if I upgrade to Kubernetes 1.32?\"\n\"Plan the upgrade of my cluster from 1.30 to 1.31 including node groups\"\n\"Are my addons compatible with EKS 1.31?\"\n\"Will my PDBs block a node group upgrade?\"\n\"I need to upgrade a 50-node cluster — what capacity do I need?\"\n\"Compare in-place vs blue-green strategy for my 200-node cluster\"\n\"My cluster is managed by Terraform — how should I do the upgrade?\"\n\"We use AL2 with custom bootstrap scripts — what breaks going to 1.33?\"\n\"We just upgraded to 1.31 — what should we validate?\"\n\"We use Pod Identity and are planning a blue-green migration — what identity work is needed?\"\n\"Give me the upgrade readiness result as JSON so I can gate our CI/CD pipeline\"\n</code></pre>\n<h3>Modes</h3>\n<table>\n<thead>\n<tr>\n<th>Mode</th>\n<th>Trigger</th>\n<th>Behavior</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Full assessment</td>\n<td>\"upgrade readiness\", \"ready to upgrade\"</td>\n<td>All 17 steps, scored report</td>\n</tr>\n<tr>\n<td>Targeted check</td>\n<td>\"deprecated APIs\", \"addon compatibility\", \"PDB check\"</td>\n<td>One dimension, focused</td>\n</tr>\n<tr>\n<td>Planning</td>\n<td>\"upgrade plan\", \"upgrade runbook\"</td>\n<td>Execution order with rollback gates</td>\n</tr>\n<tr>\n<td>Comparison</td>\n<td>\"blue-green vs in-place\"</td>\n<td>Strategy recommendation</td>\n</tr>\n<tr>\n<td>Validation</td>\n<td>\"post-upgrade check\", \"validate upgrade\"</td>\n<td>Smoke tests (Step 15)</td>\n</tr>\n</tbody>\n</table>\n<h2>Skill Structure</h2>\n<pre><code>eks-upgrade-readiness/\n├── SKILL.md                # Main skill instructions (17-step workflow)\n├── README.md               # This file\n├── CHANGELOG.md            # Version history\n├── .skilleval.yaml         # Agent Skill Eval config\n├── evals/\n│   ├── evals.json          # 24 functional evaluation scenarios\n│   └── eval_queries.json   # Trigger tests (positive and negative)\n└── references/\n    ├── safety-invariants.md         # Hard safety rules, knowledge hierarchy, operation classification\n    ├── required-check-registry.yaml # All 60+ checks with IDs, categories, and severity\n    ├── pre-flight-checks.yaml       # Blocking vs warning checks, timeouts, soak periods, rollback conditions\n    ├── api-deprecations.md          # K8s API removal schedule by version\n    ├── addon-version-matrix.md      # EKS addon compatibility (static fallback)\n    ├── capacity-planning.md         # FDCR/ODCR surge capacity guidance\n    ├── upgrade-troubleshooting.md   # Tools, feature removals, blue-green\n    ├── karpenter-checks.md          # Full 14-check Karpenter registry (KARP-01 to KARP-14)\n    ├── pre-drain-safety.md          # DRAIN-01 to DRAIN-06 detection and remediation\n    ├── al2-al2023-migration.md      # AL2→AL2023 migration assessment details\n    └── data-plane-inventory.md      # MNG, self-managed, Karpenter, Auto Mode, Fargate inventory commands\n</code></pre>\n<h2>Safety</h2>\n<p>This skill operates in <strong>read-only</strong> mode:</p>\n<ul>\n<li>No cluster modifications — upgrade actions are recommendations only</li>\n<li>No <code>update-*</code>, <code>delete-*</code>, or <code>create-*</code> API calls</li>\n<li>All mutations isolated in Step 14 Remediation Playbook (operator approval)</li>\n<li>All findings include evidence and specific remediation steps</li>\n<li>The operator reviews the report and decides whether to proceed</li>\n<li>UNKNOWN verdicts prevent false confidence (never marks missing data as PASS)</li>\n</ul>\n<h2>Non-production disclaimer</h2>\n<blockquote>\n<p>⚠️ This skill is sample code, not intended for production use without\nadditional review and testing. Validate in a non-production environment first.\nCompatibility data and version matrices are point-in-time references — always\nverify with <code>aws eks describe-addon-versions</code> for the latest data.</p>\n</blockquote>\n","files":[{"path":"CHANGELOG.md","sizeBytes":9132,"isText":true},{"path":"evals/eval_queries.json","sizeBytes":3566,"isText":true},{"path":"evals/evals.json","sizeBytes":16777,"isText":true},{"path":"README.md","sizeBytes":10592,"isText":true},{"path":"references/addon-version-matrix.md","sizeBytes":5519,"isText":true},{"path":"references/al2-al2023-migration.md","sizeBytes":6180,"isText":true},{"path":"references/api-deprecations.md","sizeBytes":3703,"isText":true},{"path":"references/capacity-planning.md","sizeBytes":6056,"isText":true},{"path":"references/data-plane-inventory.md","sizeBytes":7051,"isText":true},{"path":"references/karpenter-checks.md","sizeBytes":5619,"isText":true},{"path":"references/pre-drain-safety.md","sizeBytes":6082,"isText":true},{"path":"references/pre-flight-checks.yaml","sizeBytes":8143,"isText":true},{"path":"references/required-check-registry.yaml","sizeBytes":16426,"isText":true},{"path":"references/safety-invariants.md","sizeBytes":4195,"isText":true},{"path":"references/upgrade-troubleshooting.md","sizeBytes":11758,"isText":true},{"path":".skilleval.yaml","sizeBytes":77,"isText":true},{"path":"SKILL.md","sizeBytes":31026,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-09-17T16:54:51.227536Z","sha256":"B3F3901AC1ACC5BE2BF65D120C2C8CE88981D3813D5A0C6D0AA79A79BD0A6373","sizeBytes":59632},"review":null,"source":{"repositoryUrl":"https://github.com/aws/tools-for-devops-agent","path":"skills/eks-upgrade-readiness","license":"Apache-2.0","commit":"a9ca636abac7bde16132ce9508586143753db97a","subtreeSha":"2E0AAEBD60833BA95AE66885FC7DAED0CF8690D11406FF347D28425FFD4A9BDE","lastSyncedAt":"2026-09-25T23:11:37.941909Z"},"reviewedAt":"2026-09-17T16:56:14.866572Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/aws/tools-for-devops-agent/tree/main/skills/eks-upgrade-readiness"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install aws-tools-for-devops-agent@llmmart"},{"target":"git","command":"git clone https://github.com/aws/tools-for-devops-agent.git"}]}