一,首先查看当前证书到期时for item in `find /etc/kubernetes/pki -maxdepth 2 -name "*.crt"`;do openssl x509 -in $item -text -noout| grep Not;echo ======================$item===================;done,下面我们就来说一说关于kubernetes快速了解?我们一起去了解并探讨一下这个问题吧!

kubernetes快速了解(kubernetes更换过期证书三)

kubernetes快速了解

一,首先查看当前证书到期时

for item in `find /etc/kubernetes/pki -maxdepth 2 -name "*.crt"`;do openssl x509 -in $item -text -noout| grep Not;echo ======================$item===================;done

二,备份过期证书

cp -rp /etc/kubernetes /etc/kubernetes.bak

三,生成配置文件

kubeadm config view > /tmp/cluster.yaml

四,更新新证书

kubeadm alpha certs renew all --config=/tmp/cluster.yaml

五,重启相关服务

docker ps |grep -E 'k8s_kube-apiserver|k8s_kube-controller-manager|k8s_kube-scheduler|k8s_etcd_etcd' | awk -F ' ' '{print $1}' |xargs docker restart

六,查看证书到期时间

for item in `find /etc/kubernetes/pki -maxdepth 2 -name "*.crt"`;do openssl x509 -in $item -text -noout| grep Not;echo ======================$item===============;done

七,覆盖配置文件

rm -rf /root/.kube/

mkdir /root/.kube/

cp -i /etc/kubernetes/admin.conf /root/.kube/config

八,验证

kubectl get no

,