Skip to content

Add --cfn-disable-termination-protection flag to opt out of CloudForm… - #8900

Merged
gustavodiaz7722 merged 1 commit into
eksctl-io:mainfrom
DerekFrank:karpenter-release
Oct 9, 2026
Merged

gustavodiaz7722 merged 1 commit into
eksctl-io:mainfrom
DerekFrank:karpenter-release

Conversation

@DerekFrank

Copy link
Copy Markdown
Contributor

Description

Since #8586, eksctl creates every CloudFormation stack with termination protection enabled, with no way to opt out. eksctl delete turns protection off before deleting, which needs cloudformation:UpdateTerminationProtection. Callers whose credentials lack that permission can no longer delete the clusters they create. This hits CI systems that create and tear down clusters with tightly scoped IAM roles. #8663 asked for an option to disable this.

This adds a --cfn-disable-termination-protection flag. It is wired the same way as --cfn-disable-rollback: a ProviderConfig field exposed through ClusterProvider, read by StackCollection when it builds CreateStackInput. It goes everywhere the other --cfn-* options are registered, so create cluster, create nodegroup, etc. accept it. The default is unchanged (protection on). Like --cfn-disable-rollback, the flag can't be combined with --dry-run.

Closes #8663

Checklist

  • Added tests that cover your change (if possible)
  • Added/modified documentation as required (such as the README.md, or the userdocs directory)
  • Manually tested
  • Made sure the title of the PR is a good description that can go into the release notes
  • (Core team) Added labels for change area (e.g. area/nodegroup) and kind (e.g. kind/improvement)

Manual test

Built from this branch, us-west-2:

Step Stack EnableTerminationProtection
eksctl create cluster --without-nodegroup --cfn-disable-termination-protection eksctl-<name>-cluster false
eksctl create nodegroup --managed (no flag) eksctl-<name>-nodegroup-ng-default true

eksctl delete cluster --wait then removed both stacks (one protected, one not) and the cluster.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Hello DerekFrank 👋 Thank you for opening a Pull Request in eksctl project. The team will review the Pull Request and aim to respond within 1-10 business days. Meanwhile, please read about the Contribution and Code of Conduct guidelines here. You can find out more information about eksctl on our website

@gustavodiaz7722 gustavodiaz7722 added the kind/feature New feature or request label Oct 7, 2026
Comment thread pkg/cfn/manager/api.go
Comment thread pkg/ctl/cmdutils/cmdutils.go Outdated
@gustavodiaz7722
gustavodiaz7722 merged commit 96b398b into eksctl-io:main Oct 9, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kind/feature New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] Termination protection enabled by default in eksctl v0.218.0+ with no config flag to disable

2 participants