View a markdown version of this page

Disassociate an OIDC identity provider from your cluster - Amazon EKS
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Help improve this page

To contribute to this user guide, choose the Edit this page on GitHub link that is located in the right pane of every page.

Disassociate an OIDC identity provider from your cluster

If you disassociate an OIDC identity provider from your cluster, users included in the provider can no longer access the cluster. However, you can still access the cluster with IAM principals.

Disassociating an OIDC identity provider is a cluster update. The cluster enters the UPDATING state, and the change can take several minutes to be fully applied to the cluster’s API servers. You can track the progress of the update with the DescribeUpdate operation. If your cluster has multiple OIDC identity providers associated, you must disassociate them one at a time. Wait for each cluster update to complete before you disassociate the next provider.

  1. Open the Amazon EKS console.

  2. In the OIDC Identity Providers section, select Disassociate, enter the identity provider name, and then select Disassociate.