监控向kubelet申请证书
使用官方的yaml直接部署即可
启用TLS Bootstrap 证书签发
vim /var/lib/kubelet/config.yaml
###
serverTLSBootstrap: true ##该设置打开
###
systemctl restart kubelet
kubectl get csr
kubectl certificate approve csr-n9pvr
#自动批准首次申请证书的 CSR 请求
kubectl create clusterrolebinding node-client-auto-approve-csr --clusterrole=system:certificates.k8s.io:certificatesigningrequests:nodeclient --user=kubelet-bootstrap
# 自动批准kubelet客户端证书续签
kubectl create clusterrolebinding node-client-auto-renew-crt --clusterrole=system:certificates.k8s.io:certificatesigningrequests:selfnodeclient --group=system:nodes
# 自动批准kubelet服务端证书续签
kubectl create clusterrolebinding node-server-auto-renew-crt --clusterrole=system:certificates.k8s.io:certificatesigningrequests:selfnodeserver --group=system:nodes