adamant-kite-43734
07/10/2024, 12:07 PMgifted-eye-83270
07/10/2024, 12:14 PM[root@rke2agent1 bilge]# cat /etc/rancher/rke2/config.yaml
server: <https://rancher.exemple.com:9345>
system-default-registry: 10.0.0.10:5000
token: fuzzybunnyslippers
write-kubeconfig-mode: "0600"
node-ip: "10.0.0.5"
kube-apiserver-arg:
- authorization-mode=RBAC,Node
kubelet-arg:
- protect-kernel-defaults=true
- read-only-port=0
- authorization-mode=Webhook
kubelet-arg:
- protect-kernel-defaults=true
- read-only-port=0
- authorization-mode=Webhook
- minimum-container-ttl-duration=10s
- maximum-dead-containers-per-container=2
- maximum-dead-containers=240
- image-gc-high-threshold=85
- image-gc-low-threshold=80
hundreds-evening-84071
07/10/2024, 12:20 PMgifted-eye-83270
07/10/2024, 12:26 PMgifted-eye-83270
07/10/2024, 12:52 PM[root@rke2agent1 agent]# rke2 certificate check
INFO[0000] Agent detected, checking agent certificates
INFO[0000] Checking certificates for rke2-controller
INFO[0000] /var/lib/rancher/rke2/agent/client-rke2-controller.crt: certificate CN=system:rke2-controller is ok, expires at 2025-05-17T13:00:35Z
INFO[0000] /var/lib/rancher/rke2/agent/client-rke2-controller.crt: certificate CN=rke2-client-ca@1715943396 is ok, expires at 2034-05-15T10:56:36Z
INFO[0000] Checking certificates for kube-proxy
INFO[0000] /var/lib/rancher/rke2/agent/client-kube-proxy.crt: certificate CN=system:kube-proxy is ok, expires at 2025-05-17T13:00:35Z
INFO[0000] /var/lib/rancher/rke2/agent/client-kube-proxy.crt: certificate CN=rke2-client-ca@1715943396 is ok, expires at 2034-05-15T10:56:36Z
INFO[0000] Checking certificates for kubelet
INFO[0000] /var/lib/rancher/rke2/agent/client-kubelet.crt: certificate CN=system:node:rke2agent1,O=system:nodes is ok, expires at 2025-07-10T12:47:10Z
INFO[0000] /var/lib/rancher/rke2/agent/client-kubelet.crt: certificate CN=rke2-client-ca@1715943396 is ok, expires at 2034-05-15T10:56:36Z
INFO[0000] /var/lib/rancher/rke2/agent/serving-kubelet.crt: certificate CN=rke2agent1 is ok, expires at 2025-07-10T12:47:10Z
INFO[0000] /var/lib/rancher/rke2/agent/serving-kubelet.crt: certificate CN=rke2-server-ca@1715943396 is ok, expires at 2034-05-15T10:56:36Z
gifted-eye-83270
07/10/2024, 1:14 PM[root@rke2agent1 agent]# rke2 certificate rotate
INFO[0000] Agent detected, rotating agent certificates
INFO[0000] Rotating certificates for kube-proxy
INFO[0000] Rotating certificates for kubelet
INFO[0000] Rotating certificates for rke2-controller
INFO[0000] Successfully backed up certificates to /var/lib/rancher/rke2/agent/tls-1720617032, please restart rke2 server or agent to rotate certificates
[root@rke2agent1 agent]# systemctl start rke2-agent
[root@rke2agent1 agent]# rke2 certificate check
INFO[0000] Agent detected, checking agent certificates
INFO[0000] Checking certificates for kubelet
INFO[0000] /var/lib/rancher/rke2/agent/client-kubelet.crt: certificate CN=system:node:rke2agent1,O=system:nodes is ok, expires at 2025-07-10T13:10:41Z
INFO[0000] /var/lib/rancher/rke2/agent/client-kubelet.crt: certificate CN=rke2-client-ca@1715943396 is ok, expires at 2034-05-15T10:56:36Z
INFO[0000] /var/lib/rancher/rke2/agent/serving-kubelet.crt: certificate CN=rke2agent1 is ok, expires at 2025-07-10T13:10:40Z
INFO[0000] /var/lib/rancher/rke2/agent/serving-kubelet.crt: certificate CN=rke2-server-ca@1715943396 is ok, expires at 2034-05-15T10:56:36Z
INFO[0000] Checking certificates for rke2-controller
INFO[0000] /var/lib/rancher/rke2/agent/client-rke2-controller.crt: certificate CN=system:rke2-controller is ok, expires at 2025-05-17T12:13:19Z
INFO[0000] /var/lib/rancher/rke2/agent/client-rke2-controller.crt: certificate CN=rke2-client-ca@1715943396 is ok, expires at 2034-05-15T10:56:36Z
INFO[0000] Checking certificates for kube-proxy
INFO[0000] /var/lib/rancher/rke2/agent/client-kube-proxy.crt: certificate CN=system:kube-proxy is ok, expires at 2025-05-17T12:13:19Z
INFO[0000] /var/lib/rancher/rke2/agent/client-kube-proxy.crt: certificate CN=rke2-client-ca@1715943396 is ok, expires at 2034-05-15T10:56:36Z
hundreds-evening-84071
07/10/2024, 1:15 PMrke2-killall.sh
instead of systemctl stop rke2-agent
gifted-eye-83270
07/10/2024, 1:22 PMhundreds-evening-84071
07/10/2024, 1:32 PMclient-rke2-controller.crt: certificate CN=system:rke2-controller is ok, expires at 2025-05-17T12:13:19Z
client-kube-proxy.crt: certificate CN=system:kube-proxy is ok, expires at 2025-05-17T12:13:19Z
These certs expire in May 2025 so they have several months left...
I know docs say they will renew every time agent starts but clearly it does not
so maybe it only renews within 90-days - also for agents?
I am not sure....gifted-eye-83270
07/10/2024, 1:33 PMcreamy-pencil-82913
07/10/2024, 4:07 PMgifted-eye-83270
07/16/2024, 5:33 PM