kubectl certificate - Approve or deny certificate signing requests
kubectl certificate approve (-f FILENAME | NAME)... [--force]
kubectl certificate deny (-f FILENAME | NAME)... [--force]
Options you will use
approve NAME- add the Approved condition; for signerName kubernetes.io/kube-apiserver-client the controller-manager then signs it (status.certificate)
deny NAME- add the Denied condition: nothing will ever be issued
--force- approve/deny even if the CSR already carries the opposite condition
Examples
$ kubectl get csrCONDITION Pending until someone approves
$ kubectl certificate approve janecertificatesigningrequest.certificates.k8s.io/jane approved
$ kubectl get csr jane -o jsonpath='{.status.certificate}' | base64 -d > jane.crtthe signed certificate, PEM
Gotchas
- Approving is not issuing: CONDITION goes Approved, then Approved,Issued once the signer (kube-controller-manager) has written status.certificate. No controller-manager, no certificate.
Taught in
Try kubectl certificate in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.