Skip to content

Commit cdbe26c

Browse files
committed
[k8s] Fix CA rotate
Using admin.conf as the kubeconfig to get correct permissions to run kubectl command to update pods to use the new CA certs. Besides, now we need to create client certs on master nodes as well. Story:2008858 Task: 42379 Change-Id: I4996060dd18ef3c448d4b225caec53bf0ae0ba75
1 parent 12766ea commit cdbe26c

File tree

2 files changed

+2
-0
lines changed

2 files changed

+2
-0
lines changed

magnum/drivers/common/templates/kubernetes/fragments/rotate-kubernetes-ca-certs-master.sh

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@ set -x
77
set -eu -o pipefail
88

99
ssh_cmd="ssh -F /srv/magnum/.ssh/config root@localhost"
10+
export KUBECONFIG="/etc/kubernetes/admin.conf"
1011

1112
service_account_key=$kube_service_account_key_input
1213
service_account_private_key=$kube_service_account_private_key_input

magnum/drivers/k8s_fedora_coreos_v1/templates/kubemaster.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1067,6 +1067,7 @@ resources:
10671067
- "#!/bin/bash"
10681068
- get_file: ../../common/templates/kubernetes/fragments/upgrade-kubernetes.sh
10691069
- get_file: ../../common/templates/kubernetes/fragments/make-cert.sh
1070+
- get_file: ../../common/templates/kubernetes/fragments/make-cert-client.sh
10701071
- get_file: ../../common/templates/kubernetes/fragments/rotate-kubernetes-ca-certs-master.sh
10711072

10721073
upgrade_kubernetes_deployment:

0 commit comments

Comments
 (0)