生产二进制方式部署的K8S集群证书重签实践
一 先备份原来的证书
1
cp -r /etc/kubernetes/ssl /etc/kubernetes/sslbak
二 重签CA证书
vi /etc/kubernetes/ssl/ca-csr.json
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
{
"CN": "kubernetes",
"key": {
"algo": "rsa",
"size": 2048
},
"names": [
{
"C": "CN",
"ST": "Guangzhou",
"L"
...more >>