Recovering from expired control plane certificates¶
You can restore kubelet certificates on your OpenShift Container Platform cluster by approving pending certificate signing requests (CSRs) after control plane certificates expire. Approved CSRs return nodes to a healthy state.
Recovering from expired control plane certificates¶
You can restore kubelet certificates by manually approving pending node-bootstrapper certificate signing requests (CSRs) and, on user-provisioned installations, kubelet serving CSRs. Approved CSRs return nodes to a healthy state after control plane certificates expire.
Prerequisites
- You have access to the cluster as a user with the
cluster-adminrole. - You have access to the OpenShift CLI (
oc).
Procedure
-
Get the list of current CSRs by running the following command:
Example outputNAME AGE SIGNERNAME REQUESTOR CONDITION csr-2s94x 8m3s kubernetes.io/kubelet-serving system:node:<node_name> Pending csr-4bd6t 8m3s kubernetes.io/kubelet-serving system:node:<node_name> Pending csr-4hl85 13m kubernetes.io/kube-apiserver-client-kubelet system:serviceaccount:openshift-machine-config-operator:node-bootstrapper Pending csr-zhhhp 3m8s kubernetes.io/kube-apiserver-client-kubelet system:serviceaccount:openshift-machine-config-operator:node-bootstrapper Pending ...In the example output, CSRs with a
SIGNERNAMEofkubernetes.io/kubelet-servingare kubelet serving CSRs. You see this CSR type on user-provisioned installations. CSRs with aSIGNERNAMEofkubernetes.io/kube-apiserver-client-kubeletand anode-bootstrapperrequestor arenode-bootstrapperCSRs that you must approve to restore kubelet certificates. -
Review the details of a CSR to verify that it is valid by running the following command:
<csr_name>is the name of a CSR from the list of current CSRs. -
Approve each valid
node-bootstrapperCSR by running the following command: -
For user-provisioned installations, approve each valid kubelet serving CSR by running the following command: