Reset Kubernetes Certificate: Difference between revisions
Appearance
Created page with " sudo kubeadm certs check-expiration sudo kubeadm init phase kubelet-finalize all sudo kubeadm certs renew all sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config sud..." |
No edit summary |
||
| Line 4: | Line 4: | ||
sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config | sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config | ||
sudo chown $(id -u):$(id -g) $HOME/.kube/config | sudo chown $(id -u):$(id -g) $HOME/.kube/config | ||
Choosing certificate validity period | |||
kubeadm allows you to choose the validity period of CA and leaf certificates. That can be done by using the certificateValidityPeriod and caCertificateValidityPeriod fields of the kubeadm configuration: | |||
apiVersion: kubeadm.k8s.io/v1beta4 | |||
kind: ClusterConfiguration | |||
certificateValidityPeriod: 8760h # Default: 365 days × 24 hours = 1 year | |||
caCertificateValidityPeriod: 87600h # Default: 365 days × 24 hours * 10 = 10 years | |||
The values of the fields follow the accepted format for Go's time.Duration values, with the longest supported unit being h (hours). | |||
https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/ | |||
Latest revision as of 20:13, 6 June 2025
sudo kubeadm certs check-expiration sudo kubeadm init phase kubelet-finalize all sudo kubeadm certs renew all sudo cp -i /etc/kubernetes/admin.conf $HOME/.kube/config sudo chown $(id -u):$(id -g) $HOME/.kube/config
Choosing certificate validity period
kubeadm allows you to choose the validity period of CA and leaf certificates. That can be done by using the certificateValidityPeriod and caCertificateValidityPeriod fields of the kubeadm configuration:
apiVersion: kubeadm.k8s.io/v1beta4
kind: ClusterConfiguration
certificateValidityPeriod: 8760h # Default: 365 days × 24 hours = 1 year
caCertificateValidityPeriod: 87600h # Default: 365 days × 24 hours * 10 = 10 years
The values of the fields follow the accepted format for Go's time.Duration values, with the longest supported unit being h (hours).
https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/