Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

关于etcd证书问题 #1

Closed
zhashuyu opened this issue Dec 2, 2017 · 1 comment
Closed

关于etcd证书问题 #1

zhashuyu opened this issue Dec 2, 2017 · 1 comment

Comments

@zhashuyu
Copy link

zhashuyu commented Dec 2, 2017

关于大侠写的etcd生成证书那块,有个疑问,我发现脚本里etcd证书是在etcd节点上生成的,那么如果有三个etcd节点,就会生成三套证书,这样子的话,三个节点之间是怎么认证的,kube-apiserver和calico用的是哪套证书,怎么实现正常通信的?

@gjmzj
Copy link
Collaborator

gjmzj commented Dec 2, 2017

如果有三个etcd节点,确实生成三套证书,但是因为是同一个CA签发的,所以三个节点用各自证书能够彼此认证,关于kube-apiserver是用同一个CA签发的kubernetes证书,使用这个证书与 etcd集群之间认证交互的,关于calico 当时为了方便是直接用etcd1生成的证书与etcd集群之间交互。

@gjmzj gjmzj closed this as completed Dec 3, 2017
gjmzj pushed a commit that referenced this issue Jan 12, 2018
ogre0403 pushed a commit to ogre0403/kubeasz that referenced this issue Apr 18, 2018
Enhance easzlab#1: Setup gpu task

See merge request nchc-ai/kubeasz!2
This was referenced Jun 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants