Kubelet client certificate rotation is disabled

Manage kubelet client certificates so they are renewed before expiry.

Description

--rotate-certificates=false disables kubelet client certificate rotation. Without a separate renewal process, certificate expiry can prevent authentication to the API server.

Rotation uses a new key and certificate signing request (CSR), so approval and certificate issuance must actually work. It is separate from rotation of kubelet serving certificates.

Potential impact

  • An expired certificate can interrupt node access to the API server.
  • Missed or delayed manual renewal can increase outage-recovery work.

Remediation

  • Use rotateCertificates: true in KubeletConfiguration or --rotate-certificates=true where supported by the version.
  • Configure required CSR approval and signing permissions, and check actual certificate replacement and expiry.
  • Where manual management is necessary, provide a renewal procedure and alerts before expiry.

Examples

These excerpts compare kubelet arguments. foo/bar is a placeholder; apply the settings to the actual node’s kubelet configuration.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: foo/bar
      command: ["kubelet"]
      args: ["--rotate-certificates=false"]

Client certificate rotation is disabled, requiring a separate renewal process.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: foo/bar
      command: ["kubelet"]
      args: ["--rotate-certificates"]

The kubelet is configured to request rotation. CSR approval and signing must succeed before it can use a new certificate.

References