From 9653d2049a77f6a8ed5b979e6fe824d2c7fe6fbc Mon Sep 17 00:00:00 2001 From: Denise Schannon Date: Wed, 20 Mar 2019 15:20:58 -0700 Subject: [PATCH] cert fixes --- .../rke-clusters/certificate-rotation/_index.md | 11 ++++++++--- content/rke/v0.1.x/en/cert-mgmt/_index.md | 4 +--- 2 files changed, 9 insertions(+), 6 deletions(-) diff --git a/content/rancher/v2.x/en/cluster-provisioning/rke-clusters/certificate-rotation/_index.md b/content/rancher/v2.x/en/cluster-provisioning/rke-clusters/certificate-rotation/_index.md index 6e4d8d1d69b..6d6a8454ca1 100644 --- a/content/rancher/v2.x/en/cluster-provisioning/rke-clusters/certificate-rotation/_index.md +++ b/content/rancher/v2.x/en/cluster-provisioning/rke-clusters/certificate-rotation/_index.md @@ -5,12 +5,11 @@ weight: 2245 _Available as of v2.2.0_ -By default, Kubernetes clusters require certificates and Rancher launched Kubernetes clusters have certificates automatically generated for them. +By default, Kubernetes clusters require certificates and Rancher launched Kubernetes clusters automatically generate certificates for the Kubernetes components. Rotating these certificates is important before the certificates expire as well as if a certificate is compromised. After the certificates are rotated, the Kubernetes components are automatically restarted. > **Note:** Even though the RKE CLI can use custom certificates for the Kubernetes cluster components, Rancher currently doesn't allow the ability to upload these in Rancher Launched Kubernetes clusters. -When generating certificates, the cluster certificates are set to expire after 1 year and the CA certificate expires after 10 years. Rotating these certificates is important before the certificates expire as well as if a certificate is compromised. -After the certificates are rotated, the Kubernetes components are automatically restarted. Certificates can be rotated for the following services: +Certificates can be rotated for the following services: - etcd - kubelet @@ -31,6 +30,12 @@ Rancher launched Kubernetes clusters have the ability to rotate the auto-generat * Rotate all Service certificates (keep the same CA) * Rotate an individual service and choose one of the services from the drop down menu + > **Note:** Rotating the CA certificate will result in restarting other system pods, that will also use the new CA certificate. This includes: + > + >- Networking pods (canal, calico, flannel, and weave) + >- Ingress Controller pods + >- KubeDNS pods + 4. Click **Save**. **Results:** The selected certificates will be rotated and the related services will be restarted to start using the new certificate. diff --git a/content/rke/v0.1.x/en/cert-mgmt/_index.md b/content/rke/v0.1.x/en/cert-mgmt/_index.md index f89dcca361d..8b429b18083 100644 --- a/content/rke/v0.1.x/en/cert-mgmt/_index.md +++ b/content/rke/v0.1.x/en/cert-mgmt/_index.md @@ -18,7 +18,7 @@ You can use the CSRs and keys to sign the certificates by a real CA. After the c ## Certificate Rotation -By default, Kubernetes clusters require certificates and RKE will automatically generate certificates for the clusters. When generating certificates, the certificates in each service are set to expire after 1 year and the CA certificate expires after 10 years. Rotating these certificates are important before the certificates expire as well as if a certificate is compromised. +By default, Kubernetes clusters require certificates and RKE will automatically generate certificates for the clusters. Rotating these certificates are important before the certificates expire as well as if a certificate is compromised. After the certificates are rotated, the Kubernetes components are automatically restarted. Certificates can be rotated for the following services: @@ -107,5 +107,3 @@ INFO[0001] [certificates] Generating etcd-zzzzz certificate and key INFO[0001] Successfully Deployed state file at [./cluster.rkestate] INFO[0001] Rebuilding Kubernetes cluster with rotated certificates ``` - -