Jump to content

Reset Kubernetes Certificate: Difference between revisions

From Costa's Wiki
Created page with " sudo kubeadm certs check-expiration sudo kubeadm init phase kubelet-finalize all sudo kubeadm certs renew all sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config sud..."
 
No edit summary
 
Line 4: Line 4:
  sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
  sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
  sudo chown $(id -u):$(id -g) $HOME/.kube/config
  sudo chown $(id -u):$(id -g) $HOME/.kube/config
Choosing certificate validity period
kubeadm allows you to choose the validity period of CA and leaf certificates. That can be done by using the certificateValidityPeriod and caCertificateValidityPeriod fields of the kubeadm configuration:
apiVersion: kubeadm.k8s.io/v1beta4
kind: ClusterConfiguration
certificateValidityPeriod: 8760h # Default: 365 days × 24 hours = 1 year
caCertificateValidityPeriod: 87600h # Default: 365 days × 24 hours * 10 = 10 years
The values of the fields follow the accepted format for Go's time.Duration values, with the longest supported unit being h (hours).
https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/

Latest revision as of 20:13, 6 June 2025

sudo kubeadm certs check-expiration
sudo kubeadm init phase kubelet-finalize all
sudo kubeadm certs renew all
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config
sudo chown $(id -u):$(id -g) $HOME/.kube/config

Choosing certificate validity period

kubeadm allows you to choose the validity period of CA and leaf certificates. That can be done by using the certificateValidityPeriod and caCertificateValidityPeriod fields of the kubeadm configuration:


apiVersion: kubeadm.k8s.io/v1beta4

kind: ClusterConfiguration

certificateValidityPeriod: 8760h # Default: 365 days × 24 hours = 1 year

caCertificateValidityPeriod: 87600h # Default: 365 days × 24 hours * 10 = 10 years

The values of the fields follow the accepted format for Go's time.Duration values, with the longest supported unit being h (hours).

https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/