K8s 1.6.1集群过期证书手动更新:openssl.cnf参数缺失
Hey there, let's work through this K8s 1.6.1 certificate expiration problem together. Since upgrading to a version with auto-renewal isn't an option, manual certificate creation is our way forward—and getting the openssl.cnf file correctly configured is the first big hurdle. Below is a tailored configuration file for your cluster, along with breakdowns of the critical parameters you were missing.
完整的OpenSSL配置文件(openssl.cnf)
[req] default_bits = 2048 prompt = no default_md = sha256 distinguished_name = req_distinguished_name x509_extensions = v3_ca req_extensions = v3_req [req_distinguished_name] C = US # 替换为你的国家代码,比如CN代表中国 ST = California # 替换为你的省/州 L = San Francisco # 替换为你的城市 O = Kubernetes # 组织名,建议保持Kubernetes以匹配集群默认配置 OU = ClusterOps # 组织单元,可自定义 CN = kubernetes-ca # CA证书的通用名,固定为kubernetes-ca即可 [v3_ca] subjectKeyIdentifier = hash authorityKeyIdentifier = keyid:always,issuer basicConstraints = critical,CA:true keyUsage = critical, digitalSignature, cRLSign, keyCertSign [v3_req] basicConstraints = CA:FALSE keyUsage = nonRepudiation, digitalSignature, keyEncipherment subjectAltName = @alt_names [alt_names] DNS.1 = kubernetes DNS.2 = kubernetes.default DNS.3 = kubernetes.default.svc DNS.4 = kubernetes.default.svc.cluster.local IP.1 = 127.0.0.1 IP.2 = <你的API Server VIP> # 替换为集群实际的API Server虚拟IP IP.3 = <节点1内网IP> # 替换为集群中所有节点的内网IP,可添加多个IP.x条目 IP.4 = <节点2内网IP>
关键参数说明
- [req]段:设置默认密钥长度、哈希算法,禁用交互式输入(
prompt=no),指定证书扩展规则,避免手动输入冗余信息。 - [req_distinguished_name]:证书的身份标识字段,根据你的集群所在地调整C/ST/L,O字段保持
Kubernetes能避免组件验证时的兼容性问题。 - [v3_ca]:专门为CA证书配置的扩展,标记该证书为根CA(
basicConstraints = critical,CA:true),并赋予签署其他证书、生成证书吊销列表的权限。 - [v3_req]:针对集群组件(API Server、kubelet等)的证书扩展,禁用CA功能,指定密钥用途,最重要的是关联SAN段——这是K8s集群必须的,因为组件会通过多个DNS名和IP访问API Server,缺少SAN会导致证书验证失败。
- [alt_names]:必须包含K8s默认的DNS条目和集群内所有相关IP(API Server VIP、所有节点IP),否则组件会出现
x509: certificate is valid for ..., not ...的错误。
后续操作提示
有了正确的配置文件后,接下来的步骤可以参考:
- 备份现有证书:默认存储路径是
/etc/kubernetes/pki/,一定要先备份,避免操作失误导致集群崩溃。 - 重新生成CA证书(如果CA也过期了):
openssl req -x509 -new -nodes -keyout ca.key -subj "/CN=kubernetes-ca" -days 3650 -config openssl.cnf -out ca.crt - 为各个组件(API Server、kubelet、controller-manager等)生成CSR,用新CA签署后替换旧证书。
- 重启所有K8s组件(kube-apiserver、kube-controller-manager、kube-scheduler、kubelet)以加载新证书。
内容的提问来源于stack exchange,提问作者Bostjan
相关产品推荐
相关产品推荐

