OnCallReady

Commands

kubectl certificate - Approve or deny certificate signing requests

kubectl certificate approve (-f FILENAME | NAME)... [--force]
kubectl certificate deny (-f FILENAME | NAME)... [--force]

Options you will use

approve NAME
add the Approved condition; for signerName kubernetes.io/kube-apiserver-client the controller-manager then signs it (status.certificate)
deny NAME
add the Denied condition: nothing will ever be issued
--force
approve/deny even if the CSR already carries the opposite condition

Examples

$ kubectl get csr

CONDITION Pending until someone approves

$ kubectl certificate approve jane

certificatesigningrequest.certificates.k8s.io/jane approved

$ kubectl get csr jane -o jsonpath='{.status.certificate}' | base64 -d > jane.crt

the signed certificate, PEM

Gotchas

Taught in

Try kubectl certificate in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.