1.kubernetes集群证书过期:
操作命令:
# kubectl get nodes
Unable to connect to the server: x509: certificate has expired or is not yet valid: current time 2022-10-17T13:32:35+08:00 is after 2022-10-15T03:15:02Z
显示信息证书已经到期。
查看kubernetes集群版本:
# kubeadm version
kubeadm version: &version.Info{Major:"1", Minor:"21", GitVersion:"v1.21.2"
2.kubernetes集群证书过期操作:
2.1 备份旧的证书:
# cp -r /etc/kubernetes/pki /etc/kubernetes/pki_bak
2.2 生成新的证书:
# kubeadm certs renew all
2.3 重启相关服务:
# docker ps | grep -v pause | grep -E "etcd|scheduler|controller|apiserver" | awk '{print $1}' | awk '{print "docker","restart",$1}' | bash
2.4 查看证书时间:
# kubeadm certs check-expiration
2.5 查看集群状态:
# kubectl get nodes
NAME STATUS ROLES AGE VERSION
master Ready control-plane,master 367d v1.21.2
worker-1 Ready <none> 341d v1.21.2