# Tweets of November 30 2020


> Even though everything mandates TLS in k8s/k3s there is no good answer to updating/rotating/distributing them??

[Mon Nov 30 13:14:59 +0000 2020](https://twitter.com/miekg/status/1333399126780895232)

----

Replying to [@bboreham](https://twitter.com/bboreham/status/1333399647189159938)

> looks too high level, i\.e more focused on application getting certs not the lower level infra bits\.

[Mon Nov 30 13:22:51 +0000 2020](https://twitter.com/miekg/status/1333401106542710785)

----

Replying to [@bradfitz](https://twitter.com/bradfitz/status/1333401415625031681)

> ugh :\(

[Mon Nov 30 13:27:18 +0000 2020](https://twitter.com/miekg/status/1333402223284543489)

----

Replying to [@GuerillaNerd](https://twitter.com/craigjellick/status/1333413367726280706)

> I need to restart k3s for that too work \(at the correct time\)\. Also does that magically update the kubelet's cert \(or mine virtual kubelet thing?\)

[Mon Nov 30 14:31:54 +0000 2020](https://twitter.com/miekg/status/1333418480046141442)

----

Replying to [@tsaha](https://twitter.com/tsaha/status/1333404390577770497)

> Oh\!

[Mon Nov 30 14:34:34 +0000 2020](https://twitter.com/miekg/status/1333419154288873473)

----

Replying to [@piper\_jason and @bradfitz](https://twitter.com/piper_jason/status/1333422578875183106)

> I rather outsource this all to tailscale and use plain HTTP\. But I can't cause it's all deeply embedded in client\-go

[Mon Nov 30 14:50:33 +0000 2020](https://twitter.com/miekg/status/1333423174214705154)

----

Replying to [@bradfitz and @piper\_jason](https://twitter.com/bradfitz/status/1333423877402226688)

> hmm\.\.\.\. I got a nagging feeling that only solves half of my woos

[Mon Nov 30 15:03:55 +0000 2020](https://twitter.com/miekg/status/1333426539527098375)

----

Replying to [@Itsuugo](https://twitter.com/Itsuugo/status/1333430100369485828)

> that's seems to operate above the infrastructure tooling

[Mon Nov 30 15:44:31 +0000 2020](https://twitter.com/miekg/status/1333436756897763331)
