Generate the certificate the apiserver uses to access etcd

Eric Paris Jan 2015


kubeadm init phase certs apiserver-etcd-client [Options]


Generate the certificate the apiserver uses to access etcd, and save them into apiserver-etcd-client.cert and apiserver-etcd-client.key files.

If both files already exist, kubeadm skips the generation step and existing files will be used.

Alpha Disclaimer: this command is currently alpha.


--cert-dir="/etc/kubernetes/pki" The path where to save and store the certificates.

--config="" Path to a kubeadm configuration file.

--csr-dir="" The path to output the CSRs and private keys to

--csr-only=false Create CSRs instead of generating certificates

--kubernetes-version="stable-1" Choose a specific Kubernetes version for the control plane.

Options Inherited from Parent Commands

--azure-container-registry-config="" Path to the file containing Azure container registry configuration information.

--log-flush-frequency=5s Maximum number of seconds between log flushes

--rootfs="" [EXPERIMENTAL] The path to the 'real' host root filesystem.

--version=false Print version information and quit

See Also



January 2015, Originally compiled by Eric Paris (eparis at redhat dot com) based on the kubernetes source material, but hopefully they have been automatically generated since!

Referenced By


User Manuals