From d08fe64710b98168339125bcbfb65ab9b43a0e0c Mon Sep 17 00:00:00 2001 From: Jennifer Travinski Date: Fri, 29 Oct 2021 17:18:41 -0400 Subject: [PATCH] Added new page for webhook expiration issue --- .../expired-webhook-certificates/_index.md | 22 +++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 content/rancher/v2.6/en/troubleshooting/expired-webhook-certificates/_index.md diff --git a/content/rancher/v2.6/en/troubleshooting/expired-webhook-certificates/_index.md b/content/rancher/v2.6/en/troubleshooting/expired-webhook-certificates/_index.md new file mode 100644 index 00000000000..e8e091d6b85 --- /dev/null +++ b/content/rancher/v2.6/en/troubleshooting/expired-webhook-certificates/_index.md @@ -0,0 +1,22 @@ +--- +title: Rotation of Expired Webhook Certificates +weight: 120 +--- + +For Rancher versions that have `rancher-webhook` installed, these certificates will expire after one year. It will be necessary for you to rotate your webhook certificate when this occurs. + +Rancher will advise the community once there is a permanent solution in place for this known issue. Currently, there are two methods to work around this issue: + +##### 1. Users with cluster access, run the following commands: +``` +kubectl delete secret -n cattle-system cattle-webhook-tls +kubectl delete pod -n cattle-system -l app=rancher-webhook +``` + +##### 2. Users with no cluster access via `kubectl` + +1. Delete the `cattle-webhook-tls` secret in the `cattle-system` namespace in the local cluster. + +1. Delete the `rancher-webhook` pod in the `cattle-system` namespace in the local cluster. + +> **Note:** The webhook certificate expiration issue is not specific to `cattle-webhook-tls` as listed in the examples. You will fill in your expired certificate secret accordingly. \ No newline at end of file