mirror of https://github.com/kubernetes/kops.git
The maximum instance lifetime is an AWS only feature and specifies the maximum amount of time (in seconds) that an instance can be in service before it is terminated and replaced. A common use case might be a requirement to replace your instances on a schedule because of internal security policies or external compliance controls. |
||
|---|---|---|
| .. | ||
| data | ||
| README.md | ||
| id_rsa.pub | ||
| in-v1alpha2.yaml | ||
| kubernetes.tf | ||
README.md
Simple test of (experimental) JWKS functionality
We have to use a fixed CA because the fingerprint is inserted into the AWS WebIdentity configuration.
ca.crt & ca.key generated with:
openssl req -new -newkey rsa:512 -days 3650 -nodes -x509 -subj "/CN=kubernetes" -keyout ca.key -out ca.crt -config <(cat /etc/ssl/openssl.cnf <(printf "[ v3_ca ]\nkeyUsage = critical,keyCertSign,cRLSign"))