Edit This Page

Generates an etcd serving certificate and key


Generates the etcd serving certificate and key and saves them into etcd/server.crt and etcd/server.key files.

The certificate includes default subject alternative names and additional SANs provided by the user; default SANs are: localhost,

If both files already exist, kubeadm skips the generation step and existing files will be used.

Alpha Disclaimer: this command is currently alpha.

kubeadm alpha phase certs etcd-server [flags]


--cert-dir string     Default: "/etc/kubernetes/pki"
The path where to save the certificates
--config string
Path to kubeadm config file. WARNING: Usage of a configuration file is experimental
-h, --help
help for etcd-server