Cluster is in an unusable state (clients cannot connect to the cluster)

Last Updated : Nov 09, 2022 |
Prolog information

Condition

Clients are not able to connect to the cluster because Kubernetes certificates have expired.
To confirm that certificates have expired, enter the ccm release common-services alarmctl -l alarmEvents command and look for a certficate has expired error message.
Unable to HelmReleaseListingParser::refresh in allotted time exited with: Error: Kubernetes cluster unreachable: Get "https://<cluster FQDN>:8443/version?timeout=32s": x509: certificate has expired or is not yet valid: current time 2022-11-03T20:32:31Z is after 2022-11-02T20:58:00Z

Cause

Kubernetes certificates have expired.
Caution:
You must plan a maintenance window to perform this task. The ccm rotate-cluster-certificates command is service affecting.

Solution

  1. Log in to Cluster Control Manager with your customer account.
  2. If you have not already done so, start a screen session.
  3. Run the ccm rotate-cluster-certificates command.
    ADDITIONAL INFORMATION:
    This command can take more than 60 minutes to complete.