talos
talos copied to clipboard
etcd / k8s-aggregator CA rotation
Feature Request
It would be nice to have an option to rotate the CA for etcd and k8saggregator, like / with talosctl rotate-ca --etcd=true.
Description
Currently only the os ca and kube CA can be rotated with talosctl. To rotate the etcd CA, you must manually create a new certificate and update the machine configuration. This must be done if the etcd CA is compromised or the certificate is about to expire.