csr
eks csr, tls 인증 오류
Error from server: Get "https://10.10.20.xxx:10250/containerLogs/game-2048/deployment-2048-74cdf7657b-jshqz/app-2048": remote error: tls: internal error> kubectl get csr -A |more
NAME AGE SIGNERNAME REQUESTOR REQUESTEDDURATION CONDITION
csr-22wz5 179m kubernetes.io/kubelet-serving kubernetes-admin <none> Pending
csr-268mq 12h kubernetes.io/kubelet-serving kubernetes-admin <none> Pending
csr-27jv2 3h30m kubernetes.io/kubelet-serving kubernetes-admin <none> Pending
csr-28z9s 163m kubernetes.io/kubelet-serving kubernetes-admin <none> Pending
csr-2925l 17h kubernetes.io/kubelet-serving kubernetes-admin <none> Pending
csr-299p4 14h kubernetes.io/kubelet-serving kubernetes-admin <none> Pending
csr-2b6m8 7h37m kubernetes.io/kubelet-serving kubernetes-admin <none> Pending{ "apiVersion": "certificates.k8s.io/v1", "kind": "CertificateSigningRequest", "metadata": { "creationTimestamp": "2023-06-15T08:42:56Z", "generateName": "csr-", "name": "csr-mwg9m", "resourceVersion": "1436", "uid": "60c56b9c-6d85-41f9-ae09-a242dbb76688" }, "spec": { "extra": { "accessKeyId": [ "ASIA5ISTH5MDxxxxx" ], "arn": [ "arn:aws:sts::xxxxx:assumed-role/devops-role-20230614/i-0d53c8xxxxx3dd9" ], "canonicalArn": [ "arn:aws:iam::xxxx:role/devops-role-20230614" ], "principalId": [ "AROA5ISTH5MDNI6xxxxx" ], "sessionName": [ "i-0d53c871axxxxx" ] }, "groups": [ "system:bootstrappers", "system:nodes", "system:authenticated" ], "request": "LS0tLS1CRUdJTiBDRVJUSUZJxxxxxxJQmJEQ0NBUklDQVFBd1hURVZNQk1HQTFVRUNoTU1jM2x6ZEdWdE9tNXZaR1Z6TVVRd1FnWURWUVFERXp0egplWE4wWlcwNmJtOWtaVHBwY0MweE1DMHhNQzB4TmkweE1qRXVZWEF0Ym05eWRHaGxZWE4wTFRJdVkyOXRjSFYwClpTNXBiblJsY201aGJEQlpNQk1HQnlxR1NNNDlBZ0VHQ0NxR1NNNDlBd0VIQTBJQUJQNjc4VFMrUTduVFlvdUUKcFpHQmxaYTRSR0puRlI0ZW9mZ29BTlZ0T1k3OG9SUkdyQ3p1OGZLYVpia09sNnpoU3RnVTYxTktLaHdWekhXSApJVDlHdlk2Z1V6QlJCZ2txaGtpRzl3MEJDUTR4UkRCQ01FQUdBMVVkRVFRNU1EZUNMMmx3TFRFd0xURXdMVEUyCkxURXlNUzVoY0MxdWIzSjBhR1ZoYzNRdE1pNWpiMjF3ZFhSbExtbHVkR1Z5Ym1Gc2h3UUtDaEI1TUFvR0NDcUcKU000OUJBTUNBMGdBTUVVQ0lRQ3RJaG85YzRhQlIrVVo0bnphY3AvZjhGNWtHSTgrOTViQU5ZWEVDMWYrWkFJZwpCa2VqWHNTVHNRcEJsalNieGJ6d3ZPY056SWQwVE9ST0M4OWhMR0UxZ0tJPQotLS0tLUVORCBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0K", "signerName": "kubernetes.io/kubelet-serving", "uid": "aws-iam-authenticator:xxxxx:AROA5ISTH5xxxx", "usages": [ "digital signature", "key encipherment", "server auth" ], "username": "system:node:ip-10-10-xxx-xxxx.ap-northeast-2.compute.internal" }, "status": { "certificate": "LS0tLS1CRUdJTiBDRVJxxxxxxx1JSUM3akNDQWRhZ0F3SUJBZ0lVYXg4OXo4VU5ueXJJOGl3NDZlaGJlVG0za0JZd0RRWUpLb1pJaHZjTkFRRUwKQlFBd0ZURVRNQkVHQTFVRUF4TUthM1ZpWlhKdVpYUmxjekFlRncweU16QTJNVFV3T0RNNE1EQmFGdzB5TkRBMgpNVFF3T0RNNE1EQmFNRjB4RlRBVEJnTlZCQW9UREhONWMzUmxiVHB1YjJSbGN6RkVNRUlHQTFVRUF4TTdjM2x6CmRHVnRPbTV2WkdVNmFYQXRNVEF0TVRBdE1UWXRNVEl4TG1Gd0xXNXZjblJvWldGemRDMHlMbU52YlhCMWRHVXUKYVc1MFpYSnVZV3d3V1RBVEJnY3Foa2pPUFFJQkJnZ3Foa2pPUFFNQkJ3TkNBQVQrdS9FMHZrTzUwMktMaEtXUgpnWldXdUVSaVp4VWVIcUg0S0FEVmJUbU8vS0VVUnF3czd2SHltbVc1RHBlczRVcllGT3RUU2lvY0ZjeDFoeUUvClJyMk9vNEc0TUlHMU1BNEdBMVVkRHdFQi93UUVBd0lGb0RBVEJnTlZIU1VFRERBS0JnZ3JCZ0VGQlFjREFUQU0KQmdOVkhSTUJBZjhFQWpBQU1CMEdBMVVkRGdRV0JCVHBzeTBFdENkLzhmUEwzeTBUQWx4eTdpcm1XVEFmQmdOVgpIU01FR0RBV2dCUUhaeHREdnlzbEhYZURHaTY2SHNpV0VDb0cvakJBQmdOVkhSRUVPVEEzZ2k5cGNDMHhNQzB4Ck1DMHhOaTB4TWpFdVlYQXRibTl5ZEdobFlYTjBMVEl1WTI5dGNIVjBaUzVwYm5SbGNtNWhiSWNFQ2dvUWVUQU4KQmdrcWhraUc5dzBCQVFzRkFBT0NBUUVBTDhSQUlUM2JUZnRuWmwyUWhhTWlkRUdBWkRlbXYvVmhCVU9SMVdldQp5TGsvVEZCMFBTMkNqQjByVkc1blVTc21pK2VIa0huaE9pMEtFOGFmWVkzUi9SMWZCZnZDVEs2Q3JvdjM2OTBaCnV4U2dESklEeUhBSEk3YjNJTzhsVnJTd3J6VFphQUtZMytPNTA1U1FpYmNUY1VMNGk4UXJoWkZod1dpSGdhRUcKNTJvbkFkWVl0RUtBc3NBbGJXTWpKMnhZaW80M25nQmVsaGtUTzNFOFJhVmlzNDkwbllIZjRLUkdETDl0SytlUwpzdXpMYzZ0M1UwTU1NcFUzcWthYXl3cUg0ckdJMkVYdC8veTQ0WU1kVy8vSk5WYzdFYk1GaHR4ZW9BUVUxdjFiCmVNTGdBRmQzOHEyYzBER3NCZlJXQ21YV2pibCs2RWxVQ1NYeXpGbks4Mm1pcFE9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==", "conditions": [ { "lastTransitionTime": "2023-06-15T08:43:13Z", "lastUpdateTime": "2023-06-15T08:43:13Z", "message": "Auto approving self kubelet server certificate after SubjectAccessReview.", "reason": "AutoApproved", "status": "True", "type": "Approved" } ] } }

그래서 어떻게 하라고?

마무리
Last updated