microsoft / microsoft/pai

K8s API server's cert need renew each year

Open
#5,334 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

doc needed known issue pai-dev
Dominant language
JavaScript
Stars
2.7k
Forks
554
Avg merge
20h 42m
Merged PRs (30d)
14

Description

The k8s API server's cert will expire every year, and will cause OpenPAI cluster not available.
Certificate Management with kubeadm:
https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#automatic-certificate-renewal

image

How to fix
  1. renew k8s cert
  2. upgrade the kube-config in all worker nodes
Todo
  • Document this requirement in the repo
  • Add warning for the cert expire

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the repository's existing documentation and the linked kubeadm certificate-renewal guidance. Document the yearly API-server certificate renewal requirement, including renewing the certificate and updating kube-config on all worker nodes; the issue already identifies the required warning.

Written by the indexing model from the issue text.

Assessment

Tech stack
kubernetes
Domain
devops, documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.