As a vSphere administrator, you can change the Kubernetes API endpoint certificate. The certificate authenticates the Kubernetes control plane to DevOps engineers, both during login and subsequent interactions with the Supervisor Cluster.

Prerequisites

Verify that you have access to a CA that can sign CSRs. For DevOps engineers, the CA must be installed on their system as a trusted root.

Procedure

  1. In the vSphere Client, navigate to the Supervisor Cluster.
  2. Click Configure then under Namespaces select Certificates.
  3. In the Workload platform MTG pane, select Actions > Generate CSR.
  4. Provide the details for the certificate.
  5. Once the CSR is generated, click Copy.
  6. Sign the certificate with a CA.
  7. From the Workload platform MTG pane, select Actions > Replace Certificate.
  8. Upload the signed certificate file and click Replace Certificate.
  9. Validate the certificate on the IP address of the Kubernetes control plane.
    For example, you can open the Kubernetes CLI Tools for vSphere download page and confirm that the certificate is replaced successfully by using the browser. You can also use echo | openssl s_client -connect https://ip:6443.