mirror of
				https://github.com/kelseyhightower/kubernetes-the-hard-way.git
				synced 2025-10-31 16:22:33 +03:00 
			
		
		
		
	update docs
This commit is contained in:
		| @@ -1,12 +1,20 @@ | ||||
| # Certificate Authority | ||||
| # Setting up a Certificate Authority and TLS Cert Generation | ||||
|  | ||||
| In this lab you will setup the necessary PKI infrastructure to secure the Kuberentes components. This lab will leverage CloudFlare's PKI toolkit, [cfssl](https://github.com/cloudflare/cfssl), to bootstrap a Certificate Authority and generate TLS certificates. | ||||
|  | ||||
| This lab will setup a Certificate Authority and generated a single set of TLS certificates that can be used to secure the following Kubernetes components: | ||||
|  | ||||
| * etcd | ||||
| * Kubernetes API Server | ||||
| * Kubernetes Kubelet | ||||
|  | ||||
| In production you should strongly consider generating individual TLS certificates for each component. | ||||
|  | ||||
| ## Install CFSSL | ||||
|  | ||||
| Follow the [CFSSL installation guide](https://github.com/cloudflare/cfssl#installation) and install `cfssl` and `cfssljson` binaries. | ||||
|  | ||||
| ## Initialize a CA | ||||
| ## Setting up a Certificate Authority | ||||
|  | ||||
| ### Create the CA configuration file | ||||
|  | ||||
|   | ||||
		Reference in New Issue
	
	Block a user
	 Kelsey Hightower
					Kelsey Hightower