You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

K8s 1.6.1集群过期证书手动更新:openssl.cnf参数缺失

Hey there, let's work through this K8s 1.6.1 certificate expiration problem together. Since upgrading to a version with auto-renewal isn't an option, manual certificate creation is our way forward—and getting the openssl.cnf file correctly configured is the first big hurdle. Below is a tailored configuration file for your cluster, along with breakdowns of the critical parameters you were missing.

完整的OpenSSL配置文件(openssl.cnf)
[req]
default_bits = 2048
prompt = no
default_md = sha256
distinguished_name = req_distinguished_name
x509_extensions = v3_ca
req_extensions = v3_req

[req_distinguished_name]
C = US  # 替换为你的国家代码,比如CN代表中国
ST = California  # 替换为你的省/州
L = San Francisco  # 替换为你的城市
O = Kubernetes  # 组织名,建议保持Kubernetes以匹配集群默认配置
OU = ClusterOps  # 组织单元,可自定义
CN = kubernetes-ca  # CA证书的通用名,固定为kubernetes-ca即可

[v3_ca]
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer
basicConstraints = critical,CA:true
keyUsage = critical, digitalSignature, cRLSign, keyCertSign

[v3_req]
basicConstraints = CA:FALSE
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
subjectAltName = @alt_names

[alt_names]
DNS.1 = kubernetes
DNS.2 = kubernetes.default
DNS.3 = kubernetes.default.svc
DNS.4 = kubernetes.default.svc.cluster.local
IP.1 = 127.0.0.1
IP.2 = <你的API Server VIP>  # 替换为集群实际的API Server虚拟IP
IP.3 = <节点1内网IP>  # 替换为集群中所有节点的内网IP,可添加多个IP.x条目
IP.4 = <节点2内网IP>
关键参数说明
  • [req]段:设置默认密钥长度、哈希算法,禁用交互式输入(prompt=no),指定证书扩展规则,避免手动输入冗余信息。
  • [req_distinguished_name]:证书的身份标识字段,根据你的集群所在地调整C/ST/L,O字段保持Kubernetes能避免组件验证时的兼容性问题。
  • [v3_ca]:专门为CA证书配置的扩展,标记该证书为根CA(basicConstraints = critical,CA:true),并赋予签署其他证书、生成证书吊销列表的权限。
  • [v3_req]:针对集群组件(API Server、kubelet等)的证书扩展,禁用CA功能,指定密钥用途,最重要的是关联SAN段——这是K8s集群必须的,因为组件会通过多个DNS名和IP访问API Server,缺少SAN会导致证书验证失败。
  • [alt_names]:必须包含K8s默认的DNS条目和集群内所有相关IP(API Server VIP、所有节点IP),否则组件会出现x509: certificate is valid for ..., not ...的错误。
后续操作提示

有了正确的配置文件后,接下来的步骤可以参考:

  1. 备份现有证书:默认存储路径是/etc/kubernetes/pki/,一定要先备份,避免操作失误导致集群崩溃。
  2. 重新生成CA证书(如果CA也过期了):
    openssl req -x509 -new -nodes -keyout ca.key -subj "/CN=kubernetes-ca" -days 3650 -config openssl.cnf -out ca.crt
    
  3. 为各个组件(API Server、kubelet、controller-manager等)生成CSR,用新CA签署后替换旧证书。
  4. 重启所有K8s组件(kube-apiserver、kube-controller-manager、kube-scheduler、kubelet)以加载新证书。

内容的提问来源于stack exchange,提问作者Bostjan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 04:12:01