二、通过命令续期
2.1 修改集群内所有机器的时间,模拟证书在过期的边缘
date -s "2024-3-1 12:00"
2.2 查看证书有效期
为了更直观的看到证书的有效期!
[root@k8s01 ~]# kubeadm alpha certs check-expiration
[check-expiration] Reading configuration from the cluster...
[check-expiration] FYI: You can look at this config file with 'kubectl -n kube-system get cm kubeadm-config -oyaml'
CERTIFICATE EXPIRES RESIDUAL TIME CERTIFICATE AUTHORITY EXTERNALLY MANAGED
admin.conf Jul 23, 2024 23:08 UTC 19h no
apiserver Jul 23, 2024 23:08 UTC 19h ca no
apiserver-etcd-client Jul 23, 2024 23:08 UTC 19h etcd-ca no
apiserver-kubelet-client Jul 23, 2024 23:08 UTC 19h ca no
controller-manager.conf Jul 23, 2024 23:08 UTC 19h no
etcd-healthcheck-client Jul 23, 2024 23:08 UTC 19h etcd-ca no
etcd-peer Jul 23, 2024 23:08 UTC 19h etcd-ca no
etcd-server Jul 23, 2024 23:08 UTC 19h etcd-ca no
front-proxy-client Jul 23, 2024 23:08 UTC 19h front-proxy-ca no
scheduler.conf Jul 23, 2024 23:08 UTC 19h no
CERTIFICATE AUTHORITY EXPIRES RESIDUAL TIME EXTERNALLY MANAGED
ca Jul 21, 2033 23:08 UTC 9y no
etcd-ca Jul 21, 2033 23:08 UTC 9y no
front-proxy-ca Jul 21, 2033 23:08 UTC 9y no
[root@k8s01 ~]#