Welcome to the Linux Foundation Forum!

SSL Cert for the load balancer HAProxy

Hi,
in the training Lab 16.2. Detailed Steps, I'm getting an error when I try to join the second and third CP to the cluster because the CN of the HA proxy (k8scp) isn't included in the PKI of the cluster.

Retrying due to error: failed to request the cluster-info ConfigMap: Get "https://k8scp:6443/api/v1/namespaces/kube-public/configmaps/cluster-info?timeout=10s": tls: failed to verify certificate: x509: certificate is valid for kubeadm-mst-t-134, kubernetes, kubernetes.default, kubernetes.default.svc, kubernetes.default.svc.cluster.local, not k8scp

How do I change the cluster server certificate to include the CN of the proxy (k8scp)?

Thanks a lot.

Comments

Categories

Upcoming Training