Howto guide for Talos secret rotation #11278
Unanswered
james-callahan
asked this question in
Q&A
Replies: 1 comment 5 replies
-
|
You can rotate any of that in a non-graceful way. Talos and Kubernetes API CAs support graceful rotation today. |
Beta Was this translation helpful? Give feedback.
5 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
The machine config has several secrets in it: for each secret, there should be a documented procedure for rotating it (preferably without cluster downtime):
cluster.secretsecret.bootstraptokensecret.secretboxencryptionsecrettrustdinfo.tokencerts.etcd.key(and.crtwould need to be updated to match)certs.k8s.key(and.crtwould need to be updated to match)certs.k8saggregator.key(and.crtwould need to be updated to match)certs.k8sserviceaccount.key(also at least for our deployment, any change here would need to be synchronised with AWS federation)certs.os.keyAn example proceduce might be as simple as:
Or perhaps some way of generating a second secret; installing it as an alternative; rolling all nodes; and then removing the old secret.
Beta Was this translation helpful? Give feedback.
All reactions