{"repo":"yuyicai/update-kube-cert","free":true,"listed":false,"github":"https://github.com/yuyicai/update-kube-cert","clone":"git clone https://github.com/yuyicai/update-kube-cert.git","description":"K8s 集群证书过期处理，更新 kubeadm 生成的证书有效期为 10 年; 为新集群生成 100 年证书支持全部版本。A tool to update and extend Kubernetes certificate expiration dates to 10 years. Generate 100 years certificates for new Kubernetes cluster","language":"Shell","stars":676,"topics":["kube-cert-expired","k8s-cert-expired","kubeadm-cert-expired","kubernetes-certification","certificate","expire","kubernetes","100year","100year-certificate"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"update-kube-cert A tool to update and extend Kubernetes certificate expiration dates in kubeadm-initiated clusters. Overview This script helps you manage Kubernetes certificates by: - Extending certificate validity to 10 years for existing Kubernetes clusters. (includes both cluster with certificate expiration issues and normal cluster) - Generating long-lived CA certificates (100 years) before initializing new clusters Usage Get the Script For Existing Clusters Renew certificates to 10 years: Run on all control plane nodes (master0, master1, master2...) Terminal Output For New Clusters Generate 100 year CA certificates before running kubeadm init Just generate CA on the first control plane node (master0, which will run kubeadm init ) Key Kubeadm init Output kubeadm uses the existing CA certificates generated by the script Full terminal Output After Running Copy the admin configuration to your kubectl config directory Options Certificate Files Updated certificates files: kubeconfig files: FAQ - Can I generate CA for 100 years on an existing cluster by this script? No, this script only updates the certificates on existing clusters, not including CA. - How can I Change CA for an existing cluster? See: https://kubernetes.io/docs/tasks/tls/manual-rotation-of-ca-certificates/ - If I have a multi-master cluster, do I need to run this on all master? Yes, you should run this script on all control plane nodes, by not on worker nodes. - How to force restart control-plane pods manually?","default_branch":null,"files":null,"tree":[],"storefront":"/r/yuyicai","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/yuyicai/update-kube-cert/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}