From abf80148acb06d71c659f4b3f9de5e7c858ab1b9 Mon Sep 17 00:00:00 2001 From: Jake Hyde Date: Wed, 26 Nov 2025 18:15:30 -0500 Subject: [PATCH] Add docs for tls-additional (#1981) * Add docs for tls-additional * Address review comments * Add tls-additional docs to previous versions --- .../resources/add-tls-secrets.md | 16 +++++++++++++++ .../resources/add-tls-secrets.md | 20 +++++++++++++++++-- .../resources/add-tls-secrets.md | 16 +++++++++++++++ .../resources/add-tls-secrets.md | 16 +++++++++++++++ .../resources/add-tls-secrets.md | 16 +++++++++++++++ .../resources/add-tls-secrets.md | 18 ++++++++++++++++- 6 files changed, 99 insertions(+), 3 deletions(-) diff --git a/docs/getting-started/installation-and-upgrade/resources/add-tls-secrets.md b/docs/getting-started/installation-and-upgrade/resources/add-tls-secrets.md index 24c0bfe786e..27eff062f25 100644 --- a/docs/getting-started/installation-and-upgrade/resources/add-tls-secrets.md +++ b/docs/getting-started/installation-and-upgrade/resources/add-tls-secrets.md @@ -42,8 +42,24 @@ kubectl -n cattle-system create secret generic tls-ca \ The configured `tls-ca` secret is retrieved when Rancher starts. On a running Rancher installation the updated CA will take effect after new Rancher pods are started. +The certificate chain must be properly formatted, or components may fail to download resources from the Rancher server. + ::: +## Adding Additional CA Certificates + +If you are using a node driver that makes API requests with a different CA than the one configured for Rancher, you can add additional root certificates and certificate chains. + +Create a unique file ending in `.pem` for each certificate that is required, and use kubectl to create the +`tls-additional` secret in the `cattle-system` namespace. + +```console +kubectl -n cattle-system create secret generic tls-additional \ + --from-file=cacerts1.pem=cacerts1.pem --from-file=cacerts2.pem=cacerts2.pem +``` + +Rancher mounts these CA root certificates and certificate chains into the node driver pod during provisioning. + ## Updating a Private CA Certificate Follow the steps on [this page](update-rancher-certificate.md) to update the SSL certificate of the ingress in a Rancher [high availability Kubernetes installation](../install-upgrade-on-a-kubernetes-cluster/install-upgrade-on-a-kubernetes-cluster.md) or to switch from the default self-signed certificate to a custom certificate. diff --git a/versioned_docs/version-2.10/getting-started/installation-and-upgrade/resources/add-tls-secrets.md b/versioned_docs/version-2.10/getting-started/installation-and-upgrade/resources/add-tls-secrets.md index 3bd6babc719..27eff062f25 100644 --- a/versioned_docs/version-2.10/getting-started/installation-and-upgrade/resources/add-tls-secrets.md +++ b/versioned_docs/version-2.10/getting-started/installation-and-upgrade/resources/add-tls-secrets.md @@ -35,15 +35,31 @@ Create a file named `cacerts.pem` that only contains the root CA certificate or ``` kubectl -n cattle-system create secret generic tls-ca \ - --from-file=cacerts.pem=./cacerts.pem + --from-file=cacerts.pem ``` :::note The configured `tls-ca` secret is retrieved when Rancher starts. On a running Rancher installation the updated CA will take effect after new Rancher pods are started. +The certificate chain must be properly formatted, or components may fail to download resources from the Rancher server. + ::: +## Adding Additional CA Certificates + +If you are using a node driver that makes API requests with a different CA than the one configured for Rancher, you can add additional root certificates and certificate chains. + +Create a unique file ending in `.pem` for each certificate that is required, and use kubectl to create the +`tls-additional` secret in the `cattle-system` namespace. + +```console +kubectl -n cattle-system create secret generic tls-additional \ + --from-file=cacerts1.pem=cacerts1.pem --from-file=cacerts2.pem=cacerts2.pem +``` + +Rancher mounts these CA root certificates and certificate chains into the node driver pod during provisioning. + ## Updating a Private CA Certificate -Follow the steps on [this page](update-rancher-certificate.md) to update the SSL certificate of the ingress in a Rancher [high availability Kubernetes installation](../install-upgrade-on-a-kubernetes-cluster/install-upgrade-on-a-kubernetes-cluster.md) or to switch from the default self-signed certificate to a custom certificate. \ No newline at end of file +Follow the steps on [this page](update-rancher-certificate.md) to update the SSL certificate of the ingress in a Rancher [high availability Kubernetes installation](../install-upgrade-on-a-kubernetes-cluster/install-upgrade-on-a-kubernetes-cluster.md) or to switch from the default self-signed certificate to a custom certificate. diff --git a/versioned_docs/version-2.11/getting-started/installation-and-upgrade/resources/add-tls-secrets.md b/versioned_docs/version-2.11/getting-started/installation-and-upgrade/resources/add-tls-secrets.md index 24c0bfe786e..27eff062f25 100644 --- a/versioned_docs/version-2.11/getting-started/installation-and-upgrade/resources/add-tls-secrets.md +++ b/versioned_docs/version-2.11/getting-started/installation-and-upgrade/resources/add-tls-secrets.md @@ -42,8 +42,24 @@ kubectl -n cattle-system create secret generic tls-ca \ The configured `tls-ca` secret is retrieved when Rancher starts. On a running Rancher installation the updated CA will take effect after new Rancher pods are started. +The certificate chain must be properly formatted, or components may fail to download resources from the Rancher server. + ::: +## Adding Additional CA Certificates + +If you are using a node driver that makes API requests with a different CA than the one configured for Rancher, you can add additional root certificates and certificate chains. + +Create a unique file ending in `.pem` for each certificate that is required, and use kubectl to create the +`tls-additional` secret in the `cattle-system` namespace. + +```console +kubectl -n cattle-system create secret generic tls-additional \ + --from-file=cacerts1.pem=cacerts1.pem --from-file=cacerts2.pem=cacerts2.pem +``` + +Rancher mounts these CA root certificates and certificate chains into the node driver pod during provisioning. + ## Updating a Private CA Certificate Follow the steps on [this page](update-rancher-certificate.md) to update the SSL certificate of the ingress in a Rancher [high availability Kubernetes installation](../install-upgrade-on-a-kubernetes-cluster/install-upgrade-on-a-kubernetes-cluster.md) or to switch from the default self-signed certificate to a custom certificate. diff --git a/versioned_docs/version-2.12/getting-started/installation-and-upgrade/resources/add-tls-secrets.md b/versioned_docs/version-2.12/getting-started/installation-and-upgrade/resources/add-tls-secrets.md index 24c0bfe786e..27eff062f25 100644 --- a/versioned_docs/version-2.12/getting-started/installation-and-upgrade/resources/add-tls-secrets.md +++ b/versioned_docs/version-2.12/getting-started/installation-and-upgrade/resources/add-tls-secrets.md @@ -42,8 +42,24 @@ kubectl -n cattle-system create secret generic tls-ca \ The configured `tls-ca` secret is retrieved when Rancher starts. On a running Rancher installation the updated CA will take effect after new Rancher pods are started. +The certificate chain must be properly formatted, or components may fail to download resources from the Rancher server. + ::: +## Adding Additional CA Certificates + +If you are using a node driver that makes API requests with a different CA than the one configured for Rancher, you can add additional root certificates and certificate chains. + +Create a unique file ending in `.pem` for each certificate that is required, and use kubectl to create the +`tls-additional` secret in the `cattle-system` namespace. + +```console +kubectl -n cattle-system create secret generic tls-additional \ + --from-file=cacerts1.pem=cacerts1.pem --from-file=cacerts2.pem=cacerts2.pem +``` + +Rancher mounts these CA root certificates and certificate chains into the node driver pod during provisioning. + ## Updating a Private CA Certificate Follow the steps on [this page](update-rancher-certificate.md) to update the SSL certificate of the ingress in a Rancher [high availability Kubernetes installation](../install-upgrade-on-a-kubernetes-cluster/install-upgrade-on-a-kubernetes-cluster.md) or to switch from the default self-signed certificate to a custom certificate. diff --git a/versioned_docs/version-2.13/getting-started/installation-and-upgrade/resources/add-tls-secrets.md b/versioned_docs/version-2.13/getting-started/installation-and-upgrade/resources/add-tls-secrets.md index 24c0bfe786e..27eff062f25 100644 --- a/versioned_docs/version-2.13/getting-started/installation-and-upgrade/resources/add-tls-secrets.md +++ b/versioned_docs/version-2.13/getting-started/installation-and-upgrade/resources/add-tls-secrets.md @@ -42,8 +42,24 @@ kubectl -n cattle-system create secret generic tls-ca \ The configured `tls-ca` secret is retrieved when Rancher starts. On a running Rancher installation the updated CA will take effect after new Rancher pods are started. +The certificate chain must be properly formatted, or components may fail to download resources from the Rancher server. + ::: +## Adding Additional CA Certificates + +If you are using a node driver that makes API requests with a different CA than the one configured for Rancher, you can add additional root certificates and certificate chains. + +Create a unique file ending in `.pem` for each certificate that is required, and use kubectl to create the +`tls-additional` secret in the `cattle-system` namespace. + +```console +kubectl -n cattle-system create secret generic tls-additional \ + --from-file=cacerts1.pem=cacerts1.pem --from-file=cacerts2.pem=cacerts2.pem +``` + +Rancher mounts these CA root certificates and certificate chains into the node driver pod during provisioning. + ## Updating a Private CA Certificate Follow the steps on [this page](update-rancher-certificate.md) to update the SSL certificate of the ingress in a Rancher [high availability Kubernetes installation](../install-upgrade-on-a-kubernetes-cluster/install-upgrade-on-a-kubernetes-cluster.md) or to switch from the default self-signed certificate to a custom certificate. diff --git a/versioned_docs/version-2.9/getting-started/installation-and-upgrade/resources/add-tls-secrets.md b/versioned_docs/version-2.9/getting-started/installation-and-upgrade/resources/add-tls-secrets.md index d77cbf52fe7..27eff062f25 100644 --- a/versioned_docs/version-2.9/getting-started/installation-and-upgrade/resources/add-tls-secrets.md +++ b/versioned_docs/version-2.9/getting-started/installation-and-upgrade/resources/add-tls-secrets.md @@ -42,8 +42,24 @@ kubectl -n cattle-system create secret generic tls-ca \ The configured `tls-ca` secret is retrieved when Rancher starts. On a running Rancher installation the updated CA will take effect after new Rancher pods are started. +The certificate chain must be properly formatted, or components may fail to download resources from the Rancher server. + ::: +## Adding Additional CA Certificates + +If you are using a node driver that makes API requests with a different CA than the one configured for Rancher, you can add additional root certificates and certificate chains. + +Create a unique file ending in `.pem` for each certificate that is required, and use kubectl to create the +`tls-additional` secret in the `cattle-system` namespace. + +```console +kubectl -n cattle-system create secret generic tls-additional \ + --from-file=cacerts1.pem=cacerts1.pem --from-file=cacerts2.pem=cacerts2.pem +``` + +Rancher mounts these CA root certificates and certificate chains into the node driver pod during provisioning. + ## Updating a Private CA Certificate -Follow the steps on [this page](update-rancher-certificate.md) to update the SSL certificate of the ingress in a Rancher [high availability Kubernetes installation](../install-upgrade-on-a-kubernetes-cluster/install-upgrade-on-a-kubernetes-cluster.md) or to switch from the default self-signed certificate to a custom certificate. \ No newline at end of file +Follow the steps on [this page](update-rancher-certificate.md) to update the SSL certificate of the ingress in a Rancher [high availability Kubernetes installation](../install-upgrade-on-a-kubernetes-cluster/install-upgrade-on-a-kubernetes-cluster.md) or to switch from the default self-signed certificate to a custom certificate.