Review kubelet serving certificate rotation

Renew kubelet serving certificates before expiry and issue them only to verified nodes.

Description

If kubelet serving certificates are not renewed in time, expiry can prevent API server connections to nodes. Automatic renewal requires RotateKubeletServerCertificate, serverTLSBootstrap: true and a working CSR approval and signing process.

Kubernetes’ built-in approvers do not automatically approve kubelet serving-certificate CSRs. Use a validating external approver or manual process, separately from client certificate rotation.

Potential impact

  • Serving-certificate expiry can interrupt node management operations such as log retrieval.
  • Approving unverified CSRs can issue certificates that impersonate other nodes.

Remediation

  • Enable the feature and serverTLSBootstrap: true in a supported kubelet configuration.
  • Configure approval and signing that verify node identity and requested DNS/IP addresses. Do not approve every request indiscriminately.
  • Test actual serving-certificate replacement and API server CA verification, and monitor expiry.

Examples

These KubeletConfiguration excerpts compare only the feature gate. They do not include the complete renewal settings or CSR approval process.

Before

yaml
apiVersion: kubelet.config.k8s.io/v1beta1
kind: KubeletConfiguration
featureGates:
  RotateKubeletServerCertificate: false

The serving-certificate rotation feature is disabled. Without separate certificate management, expiry can prevent connectivity.

After

yaml
apiVersion: kubelet.config.k8s.io/v1beta1
kind: KubeletConfiguration
featureGates:
  RotateKubeletServerCertificate: true

The feature gate is enabled. It does not start renewal by itself; serverTLSBootstrap and an approval/issuance process are also needed.

References