Rotating cluster certificates manually

Last Updated : Apr 02, 2026 |
Prolog information

Condition

The Common Services cluster contains internal Kubernetes (k8s) certificates that require manual rotation. These certificates are not rotated automatically or renewed during a cluster upgrade.
You must monitor certificate validity and rotate the certificates manually before they expire. If the certificates expire, the cluster becomes unstable or unusable and requires recovery or reinstallation.
  • Warning alarm displays every 5 days if the certificates expire in 31 to 60 days.
  • Major alarm displays every 5 days if the certificates expire in 15 to 30 days.
  • Critical alarm displays every day if the certificates expire in 10 days or less.

Solution

  1. To check when the cluster certificates expire, run the clusterNodeCertificateExpiryCheck command.
  2. To manually rotate the certificates before they expire, run ccm rotate-cluster-certificates during a maintenance window.
    ADDITIONAL INFORMATION:
    This process can take up to two hours to complete.
    If the certificates have already expired, you must reinstall the cluster.