K8s集群证书续签(kubeadm)步骤:
# 查看证书有效期
kubeadm certs check-expiration
# 备份旧证书
cp -r /etc/kubernetes/pki /etc/kubernetes/pki.old
# 续签证书
kubeadm certs renew all
# 更新kubectl配置
cp -f /etc/kubernetes/admin.conf $HOME/.kube/config
# 重启相关服务,使用新的证书
docker ps | egrep "etcd|kube-apiserver|kube-controller-manager|kube-scheduler" |awk '!/pause/{print $1}' |xargs -i docker restart {}