Skip to main content

Update certificates for system components in a Managed Kubernetes cluster

Current certificates are required for Kubernetes system components to interact.They are updated automatically every 30 days.If an error occurs during certificate renewal, you can update the certificates in the Control panel or via the Managed Kubernetes API.

Information about certificate updates is reflected in the cluster logs.

The kubeconfig file changes every time certificates are updated, so you need to reconnect to the cluster.To avoid having to reconnect, configure updates via ServiceAccount Token.

Update certificates when an error occurs

If an error ROTATE CERTS = ERROR occurred during the automatic certificate update, you can update the certificates in the Control panel or via the Managed Kubernetes API.

  1. In the Control panel, click Products in the top menu and select Managed Kubernetes.
  2. In the Clusters section, open the cluster page → Settings tab.
  3. In the Cluster access block, click Update certificates.
  4. Reconnect to the cluster.

Configure certificate updates via ServiceAccount Token

A ServiceAccount Token is an authorization method for the Kubernetes API.It allows you not to update the kubeconfig file after every certificate renewal.

The process of obtaining a ServiceAccount Token depends on the Kubernetes version:

For Kubernetes version 1.23 and lower

  1. Create a ServiceAccount:

    kubectl -n kube-system create serviceaccount <serviceaccount_name>

    Specify <serviceaccount_name> — the name of the service account.

  2. Create a ClusterRoleBinding (a group for the new user) and add a role with administrator rights (cluster-admin):

    kubectl create clusterrolebinding <clusterrolebinding_name> --clusterrole=cluster-admin --serviceaccount=kube-system:<serviceaccount_name>

    Specify <clusterrolebinding_name> — the name of the group for the new user.

  3. Add the name of the created ServiceAccount secret that stores the token to the TOKENNAME environment variable:

    export TOKENNAME=$(kubectl -n kube-system get serviceaccount/<serviceaccount_name> -o jsonpath='{.secrets[0].name}')
  4. Add the decoded token from the secret to the TOKEN environment variable:

    export TOKEN=$(kubectl -n kube-system get secret $TOKENNAME -o jsonpath='{.data.token}' | base64 --decode)
  5. Check if the token works — make a request to the Kubernetes API with the token in the header:

    curl -k -H "Authorization: Bearer $TOKEN" -X GET "https://<kube_api_ip>:6443/api/v1/nodes" | json_pp

    Specify <kube_api_ip> — the cluster IP address in the Control panel.

  6. Add the ServiceAccount to the kubeconfig file:

    kubectl config set-credentials <serviceaccount_name> --token=$TOKEN
  7. Switch the context:

    kubectl config set-context --current --user=<serviceaccount_name>
  8. Check if it works — make any request to the Kubernetes API. For example, request a list of cluster nodes:

    kubectl get nodes
  9. The updated kubeconfig file will be in the home directory $HOME/.kube/config.

For Kubernetes version 1.24 and higher

  1. Create a ServiceAccount:

    kubectl -n kube-system create serviceaccount <serviceaccount_name>

    Specify <serviceaccount_name> — the name of the service account.

  2. Create a ClusterRoleBinding (a group for the new user) and add a role with administrator rights (cluster-admin):

    kubectl create clusterrolebinding <clusterrolebinding_name> --clusterrole=cluster-admin --serviceaccount=kube-system:<serviceaccount_name>

    Specify <clusterrolebinding_name> — the name of the group for the new user.

  3. Get the name of the secret of the created ServiceAccount that stores the token:

    kubectl -n kube-system apply -f - <<EOF
    apiVersion: v1
    kind: Secret
    metadata:
    name: <serviceaccount_name>-token
    annotations:
    kubernetes.io/service-account.name: <serviceaccount_name>
    type: kubernetes.io/service-account-token
    EOF
  4. Add the decoded token from the secret to the TOKEN environment variable:

    export TOKEN=$(kubectl -n kube-system get secret <serviceaccount_name>-token -o jsonpath='{.data.token}' | base64 --decode)
  5. Check if the token works — make a request to the Kubernetes API with the token in the header:

    curl -k -H "Authorization: Bearer $TOKEN" -X GET "https://<kube_api_ip>:6443/api/v1/nodes" | json_pp

    Specify <kube_api_ip> — the cluster IP address in the Control panel.

  6. Add the ServiceAccount to the kubeconfig file:

    kubectl config set-credentials <serviceaccount_name> --token=$TOKEN
  7. Switch the context:

    kubectl config set-context --current --user=<serviceaccount_name>
  8. Check if it works — make any request to the Kubernetes API. For example, request a list of cluster nodes:

    kubectl get nodes
  9. The updated kubeconfig file will be in the home directory $HOME/.kube/config.