Tweets of November 30 2020

November 30, 2020


Even though everything mandates TLS in k8s/k3s there is no good answer to updating/rotating/distributing them??

looks too high level, i.e more focused on application getting certs not the lower level infra bits.

ugh :(

I need to restart k3s for that too work (at the correct time). Also does that magically update the kubelet’s cert (or mine virtual kubelet thing?)

I rather outsource this all to tailscale and use plain HTTP. But I can’t cause it’s all deeply embedded in client-go

hmm.... I got a nagging feeling that only solves half of my woos

that’s seems to operate above the infrastructure tooling

