Hands-on Lab·Kubernetes and Cloud Native Security Associate
Cluster PKI and Certificate Signing Requests
Every component of this cluster proves who it is with a certificate, and all of them trace back to files in one directory. This guide counts the authorities, reads the expiry dates, and then uses the CSR API to have the cluster CA issue a brand new identity.
Platform Security Guide 35 of 42 Advanced
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 20 min
- Reviewed25 August 2026
Written against the versions above. kubeadm creates three CAs and issues leaf certificates valid for one year. There is no revocation in the apiserver - a certificate is valid until it expires.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
-
How many certificate authorities this cluster has
-
What the cluster CA is, and how long it lasts
-
What the apiserver certificate says about itself
-
The expiry dates, in one command
-
Asking the cluster CA for an identity
-
Approving it, and reading what came back