Description
--rotate-certificates=false disables kubelet client certificate rotation. Without a separate renewal process, certificate expiry can prevent authentication to the API server.
Rotation uses a new key and certificate signing request (CSR), so approval and certificate issuance must actually work. It is separate from rotation of kubelet serving certificates.
Potential impact
- An expired certificate can interrupt node access to the API server.
- Missed or delayed manual renewal can increase outage-recovery work.
Remediation
- Use
rotateCertificates: truein KubeletConfiguration or--rotate-certificates=truewhere supported by the version. - Configure required CSR approval and signing permissions, and check actual certificate replacement and expiry.
- Where manual management is necessary, provide a renewal procedure and alerts before expiry.
Examples
These excerpts compare kubelet arguments. foo/bar is a placeholder; apply the settings to the actual node’s kubelet configuration.
Before
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: foo/bar
command: ["kubelet"]
args: ["--rotate-certificates=false"]
Client certificate rotation is disabled, requiring a separate renewal process.
After
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: foo/bar
command: ["kubelet"]
args: ["--rotate-certificates"]
The kubelet is configured to request rotation. CSR approval and signing must succeed before it can use a new certificate.