0

I have running kubernetes installed by kubespray.

Due to default "kubelet_rotate_certificates" configuration, kubelet certificates is recreated periodically.

What i want to know is whether it is possible to add SAN(Subject Alternatives Names) to kubelet client-certificate file?

kubelet client certificate is re-created with only CN (node's hostname).

** kubelet client-certificate location : /var/lib/kubelet/pki/kubelet-client-2022-06-14-07-49-59.pem

aspirant75
  • 127
  • 1
  • 2
  • 10

0 Answers0