Description
If kubelet serving certificates are not renewed in time, expiry can prevent API server connections to nodes. Automatic renewal requires RotateKubeletServerCertificate, serverTLSBootstrap: true and a working CSR approval and signing process.
Kubernetes’ built-in approvers do not automatically approve kubelet serving-certificate CSRs. Use a validating external approver or manual process, separately from client certificate rotation.
Potential impact
- Serving-certificate expiry can interrupt node management operations such as log retrieval.
- Approving unverified CSRs can issue certificates that impersonate other nodes.
Remediation
- Enable the feature and
serverTLSBootstrap: truein a supported kubelet configuration. - Configure approval and signing that verify node identity and requested DNS/IP addresses. Do not approve every request indiscriminately.
- Test actual serving-certificate replacement and API server CA verification, and monitor expiry.
Examples
These KubeletConfiguration excerpts compare only the feature gate. They do not include the complete renewal settings or CSR approval process.
Before
apiVersion: kubelet.config.k8s.io/v1beta1
kind: KubeletConfiguration
featureGates:
RotateKubeletServerCertificate: false
The serving-certificate rotation feature is disabled. Without separate certificate management, expiry can prevent connectivity.
After
apiVersion: kubelet.config.k8s.io/v1beta1
kind: KubeletConfiguration
featureGates:
RotateKubeletServerCertificate: true
The feature gate is enabled. It does not start renewal by itself; serverTLSBootstrap and an approval/issuance process are also needed.