Skip to content

How do I replace a non public facing K3s active cluster with corperate signed CA certs? #12563

Answered by brandond
davehouser1 asked this question in Q&A
Discussion options

You must be logged in to vote

I would not recommend trying to rotate an existing cluster from the default autogenerated CA to an existing corp CA, especially if you are struggling to understand all the moving pieces. Build a new cluster that uses your corp certs from the start, as covered in the docs.

Replies: 1 comment 5 replies

Comment options

You must be logged in to vote
5 replies
@davehouser1
Comment options

@brandond
Comment options

brandond Jul 1, 2025
Collaborator

@davehouser1
Comment options

@brandond
Comment options

brandond Jul 2, 2025
Collaborator

Answer selected by davehouser1
@davehouser1
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants