Connecting to a Cluster Using an X.509 Certificate
Scenario
This section describes how to obtain the cluster certificate from the console and use it access Kubernetes clusters.
Procedure
- Log in to the CCE console and click the cluster name to access the cluster console.
- Choose Cluster Information from the navigation pane and click Download next to Certificate Authentication in the Connection Information area.
- In the Obtain Certificate dialog box displayed, select the certificate expiration time and download the X.509 certificate of the cluster as prompted.
- The downloaded certificate contains three files: client.key, client.crt, and ca.crt. Keep these files secure.
- Certificates are not required for mutual access between containers in a cluster.
- Call native Kubernetes APIs using the cluster certificate.
For example, run the curl command to call an API to view the pod information. In the following information,192.168.***.***:5443 indicates the IP address of the API server in the cluster.
curl --cacert ./ca.crt --cert ./client.crt --key ./client.key https://192.168.***.***:5443/api/v1/namespaces/default/pods/
For more cluster APIs, see Kubernetes APIs.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot