kubernetes-sigs / cluster-api-provider-azure

Cluster API implementation for Microsoft Azure
https://capz.sigs.k8s.io/
Apache License 2.0
295 stars 425 forks source link

Automatic certificate rotation #1660

Open ritazh opened 3 years ago

ritazh commented 3 years ago

/kind documentation

Describe the solution you'd like [A clear and concise description of what you want to happen.] Documentation, guidance, and known issues around how to perform cert rotation for both leaf and CA cert rotation. Beyond these: https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#automatic-certificate-renewal https://cluster-api.sigs.k8s.io/tasks/certs/using-custom-certificates.html

Anything else you would like to add: [Miscellaneous information that will assist in solving the issue.]

Environment:

sayantani11 commented 3 years ago

@ritazh Can you provide a bit more insight on the task?

sayantani11 commented 3 years ago

I would like to work on it, but would require some help

ritazh commented 3 years ago

It would be great to have a step-by-step guide to help users get started on how to perform cert rotation for both leaf and CA cert rotation, including known issues and recommendations. The links above are pretty high level. FYI @devigned

k8s-triage-robot commented 2 years ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues and PRs.

This bot triages issues and PRs according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

devigned commented 2 years ago

/remove-lifecycle stale

sayantani11 commented 2 years ago

I would like to try this issue.

k8s-triage-robot commented 2 years ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues and PRs.

This bot triages issues and PRs according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

shysank commented 2 years ago

/remove-lifecycle stale

k8s-triage-robot commented 2 years ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues and PRs.

This bot triages issues and PRs according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

jackfrancis commented 2 years ago

/remove-lifecycle stale

k8s-triage-robot commented 2 years ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues and PRs.

This bot triages issues and PRs according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

jackfrancis commented 2 years ago

/remove-lifecycle stale

dtzar commented 1 year ago

Lots of things changing in this space, so probably best to document after things here are merged. i.e. https://github.com/kubernetes-sigs/cluster-api-provider-azure/issues/915

k8s-triage-robot commented 1 year ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

nawazkh commented 1 year ago

Housekeeping! Do we keep this open @CecileRobertMichon @dtzar ?

dtzar commented 1 year ago

I feel like this should be at the CAPI level first

CecileRobertMichon commented 1 year ago

Agree ^

dtzar commented 1 year ago

/remove-lifecycle stale

Still a valid request. Even when/if an implementation or spec for CAPI is addressed, it's possible we might still want an Azure-specific implementation (i.e. connecting the CAPZ machine control plane cluster secrets with Key Vault and then using Key Vault for rotation)

k8s-triage-robot commented 1 year ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

nawazkh commented 1 year ago

/remove-lifecycle stale

k8s-triage-robot commented 9 months ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

dtzar commented 9 months ago

/remove-lifecycle stale /lifecycle frozen