首先查看当前证书到期时间
for item in `find /etc/kubernetes/pki -maxdepth 2 -name "*.crt"`;do openssl x509 -in $item -text -noout| grep Not;echo ======================$item===================;done
备份过期证书
cp -rp /etc/kubernetes /etc/kubernetes.bak
生成配置文件
kubeadm config view > /tmp/cluster.yaml
更新新证书
kubeadm alpha certs renew all --config=/tmp/cluster.yaml
重启相关服务
docker ps |grep -E 'k8s_kube-apiserver|k8s_kube-controller-manager|k8s_kube-scheduler|k8s_etcd_etcd' | awk -F ' ' '{print $1}' |xargs docker restart
查看证书到期时间
for item in `find /etc/kubernetes/pki -maxdepth 2 -name "*.crt"`;do openssl x509 -in $item -text -noout| grep Not;echo ======================$item===============;done
覆盖配置文件
rm -rf /root/.kube/
mkdir /root/.kube/
cp -i /etc/kubernetes/admin.conf /root/.kube/config
验证
kubectl get no