Hands-on Lab·Kubernetes and Cloud Native Security Associate
kubeconfig Files and Client Certificates
Client security is a Domain 2 competency and a kubeconfig is the client. This guide opens the ones kubeadm wrote, reads the certificate inside the admin file, and finds that it is not the identity most people assume.
Cluster Component Security Guide 16 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 16 min
- Reviewed25 August 2026
Written against the versions above. kubeadm v1.36. The `admin.conf` / `super-admin.conf` split arrived in kubeadm 1.29 - before that, `admin.conf` carried `system:masters`. If your knowledge predates it, this page is the correction.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 13 - the other certificate identity on this node.
-
Five files, and one you may not have seen
-
Who admin.conf actually is