hundreds-farmer-86572
10/15/2024, 12:20 PMopenssl genrsa -out newuser.key 2048
openssl req -new -key newuser.key -out newuser.csr -subj "/CN=mike/O=Devops"
-----------------------------------------------------------
apiVersion: certificates.k8s.io/v1
kind: CertificateSigningRequest
metadata:
name: mike
spec:
groups:
- system:authenticated
request: $(cat newuser.csr | base64 | tr -d "\n")
signerName: kubernetes.io/kube-apiserver-client
usages:
- client auth
--------------------------------------------------------------------
kubectl get csr
kubectl certificate approve mike
kubectl get csr mike -o jsonpath='{.status.certificate}' | base64 -d >> newuser.crt