mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-29 06:29:34 +00:00
Fix tabs: add import statements, specify value, spacing
This commit is contained in:
+7
-4
@@ -3,6 +3,9 @@ title: Certificate Rotation
|
||||
weight: 2040
|
||||
---
|
||||
|
||||
import Tabs from '@theme/Tabs';
|
||||
import TabItem from '@theme/TabItem';
|
||||
|
||||
> **Warning:** Rotating Kubernetes certificates may result in your cluster being temporarily unavailable as components are restarted. For production environments, it's recommended to perform this action during a maintenance window.
|
||||
|
||||
By default, Kubernetes clusters require certificates and Rancher launched Kubernetes clusters automatically generate certificates for the Kubernetes components. Rotating these certificates is important before the certificates expire as well as if a certificate is compromised. After the certificates are rotated, the Kubernetes components are automatically restarted.
|
||||
@@ -10,7 +13,7 @@ By default, Kubernetes clusters require certificates and Rancher launched Kubern
|
||||
Certificates can be rotated for the following services:
|
||||
|
||||
<Tabs>
|
||||
<TabItem label="RKE">
|
||||
<TabItem value="RKE">
|
||||
|
||||
- etcd
|
||||
- kubelet (node certificate)
|
||||
@@ -21,7 +24,7 @@ Certificates can be rotated for the following services:
|
||||
- kube-controller-manager
|
||||
|
||||
</TabItem>
|
||||
<TabItem label="RKE2">
|
||||
<TabItem value="RKE2">
|
||||
|
||||
- admin
|
||||
- api-server
|
||||
@@ -59,12 +62,12 @@ Rancher launched Kubernetes clusters have the ability to rotate the auto-generat
|
||||
### Additional Notes
|
||||
|
||||
<Tabs>
|
||||
<TabItem label="RKE">
|
||||
<TabItem value="RKE">
|
||||
|
||||
Even though the RKE CLI can use custom certificates for the Kubernetes cluster components, Rancher currently doesn't allow the ability to upload these in Rancher launched Kubernetes clusters.
|
||||
|
||||
</TabItem>
|
||||
<TabItem label="RKE2">
|
||||
<TabItem value="RKE2">
|
||||
|
||||
In RKE2, both etcd and control plane nodes are treated as the same `server` concept. As such, when rotating certificates of services specific to either of these components will result in certificates being rotated on both. The certificates will only change for the specified service, but you will see nodes for both components go into an updating state. You may also see worker only nodes go into an updating state. This is to restart the workers after a certificate change to ensure they get the latest client certs.
|
||||
|
||||
|
||||
+8
-2
@@ -4,6 +4,9 @@ description: Learn about cluster cleanup when removing nodes from your Rancher-l
|
||||
weight: 2055
|
||||
---
|
||||
|
||||
import Tabs from '@theme/Tabs';
|
||||
import TabItem from '@theme/TabItem';
|
||||
|
||||
This section describes how to disconnect a node from a Rancher-launched Kubernetes cluster and remove all of the Kubernetes components from the node. This process allows you to use the node for other purposes.
|
||||
|
||||
When you use Rancher to install Kubernetes on new nodes in an infrastructure provider, resources (containers/virtual network interfaces) and configuration items (certificates/configuration files) are created.
|
||||
@@ -56,7 +59,8 @@ For registered clusters, the process for removing Rancher is a little different.
|
||||
After the registered cluster is detached from Rancher, the cluster's workloads will be unaffected and you can access the cluster using the same methods that you did before the cluster was registered into Rancher.
|
||||
|
||||
<Tabs>
|
||||
<TabItem label="By UI / API">
|
||||
<TabItem value="By UI / API">
|
||||
|
||||
>**Warning:** This process will remove data from your cluster. Make sure you have created a backup of files you want to keep before executing the command, as data will be lost.
|
||||
|
||||
After you initiate the removal of a registered cluster using the Rancher UI (or API), the following events occur.
|
||||
@@ -69,8 +73,10 @@ After you initiate the removal of a registered cluster using the Rancher UI (or
|
||||
|
||||
**Result:** All components listed for registered clusters in [What Gets Removed?](#what-gets-removed) are deleted.
|
||||
|
||||
|
||||
</TabItem>
|
||||
<TabItem label="By Script">
|
||||
<TabItem value="By Script">
|
||||
|
||||
Rather than cleaning registered cluster nodes using the Rancher UI, you can run a script instead.
|
||||
|
||||
>**Prerequisite:**
|
||||
|
||||
Reference in New Issue
Block a user