You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将自签名用户证书转为Kubernetes kubeconfig内联格式?

How to Inline .crt and .key Files into a Kubernetes kubeconfig

Got it, let's walk through how to convert your user's .crt and .key files into the inline base64 format required for a kubeconfig. This way you can distribute a single self-contained config file instead of multiple certificate files.

Step 1: Encode the Certificate and Key to Base64 (Without Line Breaks)

Kubernetes expects inline certificate data to be a single-line base64 string (no newlines). You can generate this with simple shell commands:

  • For your .crt file:

    cat your-user.crt | base64 | tr -d '\n'
    

    Copy the output string—this is what you'll use for client-certificate-data in the kubeconfig.

  • For your .key file:

    cat your-user.key | base64 | tr -d '\n'
    

    Copy this output for client-key-data.

Step 2: Add the Inlined Data to Your Kubeconfig

You have two options here: using kubectl to automate the process, or manually editing the kubeconfig file.

Option A: Use kubectl (Easiest Method)

The kubectl config command can directly take your certificate files and handle the encoding/inline conversion for you. Run:

kubectl config set-credentials <your-user-name> \
  --client-certificate=your-user.crt \
  --client-key=your-user.key

This will update your current kubeconfig (usually ~/.kube/config) with the user entry, automatically inlining the certificate and key data.

Option B: Manually Edit the Kubeconfig

If you prefer to build the kubeconfig from scratch or modify an existing one, open the file and add/update the users section with your base64-encoded strings:

apiVersion: v1
kind: Config
users:
- name: <your-user-name>
  user:
    client-certificate-data: <PASTE-YOUR-BASE64-CRT-HERE>
    client-key-data: <PASTE-YOUR-BASE64-KEY-HERE>
# Don't forget to link this user to a cluster and context as needed
clusters:
- name: <your-cluster-name>
  cluster:
    certificate-authority-data: <BASE64-ENCODED-CA-CRT> # If using a custom CA
    server: https://your-cluster-api-server:6443
contexts:
- name: <your-context-name>
  context:
    cluster: <your-cluster-name>
    user: <your-user-name>
current-context: <your-context-name>

Step 3: Verify the Inlined Data

To confirm everything is set up correctly, run:

kubectl config view --minify --flatten

Look for the client-certificate-data and client-key-data fields—they should be long single-line base64 strings, matching the outputs from Step 1.

That's it! Your kubeconfig is now self-contained and ready to distribute to the user.

内容的提问来源于stack exchange,提问作者ChrJantz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:50:20