Fixup kubelet.conf to point to kubelet-client-current.pem (#7347)

c9c0c01de0 only fix the problem for new clusters

Signed-off-by: Etienne Champetier <e.champetier@ateme.com>
(cherry picked from commit 14b63ede8c)

Conflicts:
	roles/kubernetes/master/tasks/kubelet-fix-client-cert-rotation.yml
This commit is contained in:
Etienne Champetier 2021-03-09 02:55:00 -05:00 committed by Kubernetes Prow Robot
parent 0ea43289e2
commit c22915a08c
2 changed files with 22 additions and 0 deletions

View file

@ -0,0 +1,18 @@
---
- name: Fixup kubelet client cert rotation 1/2
lineinfile:
path: "{{ kube_config_dir }}/kubelet.conf"
regexp: '^ client-certificate-data: '
line: ' client-certificate: /var/lib/kubelet/pki/kubelet-client-current.pem'
backup: yes
notify:
- "Master | reload kubelet"
- name: Fixup kubelet client cert rotation 2/2
lineinfile:
path: "{{ kube_config_dir }}/kubelet.conf"
regexp: '^ client-key-data: '
line: ' client-key: /var/lib/kubelet/pki/kubelet-client-current.pem'
backup: yes
notify:
- "Master | reload kubelet"

View file

@ -62,3 +62,7 @@
- name: Include kubeadm secondary server apiserver fixes - name: Include kubeadm secondary server apiserver fixes
include_tasks: kubeadm-fix-apiserver.yml include_tasks: kubeadm-fix-apiserver.yml
- name: Include kubelet client cert rotation fixes
include_tasks: kubelet-fix-client-cert-rotation.yml
when: kubelet_rotate_certificates