Jump to content

Reset Kubernetes Certificate

From Costa's Wiki
sudo kubeadm certs check-expiration
sudo kubeadm init phase kubelet-finalize all
sudo kubeadm certs renew all
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config

Choosing certificate validity period

kubeadm allows you to choose the validity period of CA and leaf certificates. That can be done by using the certificateValidityPeriod and caCertificateValidityPeriod fields of the kubeadm configuration:


apiVersion: kubeadm.k8s.io/v1beta4

kind: ClusterConfiguration

certificateValidityPeriod: 8760h # Default: 365 days × 24 hours = 1 year

caCertificateValidityPeriod: 87600h # Default: 365 days × 24 hours * 10 = 10 years

The values of the fields follow the accepted format for Go's time.Duration values, with the longest supported unit being h (hours).

https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/