kubeadm证书续期

查看现有证书到期时间
$ kubeadm alpha certs check-expiration
# 使用二进制更新证书
$ kubeadm alpha certs renew all
# 每月的最后1天
0 0 L * /usr/bin/kubeadm alpha certs renew all

查看证书
[root@master1 ~]# cd /etc/kubernetes/pki
[root@master1 ~]# openssl x509 -in apiserver.crt -noout -text |grep Not
Not Before: Nov 13 03:43:30 2019 GMT
Not After : Nov 17 01:41:50 2020 GMT
[root@master1 ~]# openssl x509 -in front-proxy-client.crt -noout -text |grep Not
Not Before: Nov 13 03:43:23 2019 GMT

配置远程管理主机

mkdir /root/.kube
将master主机的 /root/.kube 目录下的 config copy至此
cd /root/.kube
scp master1:/root/.kube/config .
scp master1:/bin/kubectl /bin/
kubectl config view
or
kubectl config view —kubeconfig=/root/.kube/config
echo ‘export KUBECONFIG=/root/.kube/config’ >> /etc/profile
source /etc/profile