How to Renew Envoy Pod TLS Certificates
One year after a Swimlane SPI installation, the envoy pod self-signed TLS certificate created during the installation will expire. A feature to auto-renew these certs at thirty days prior to expiration is available on Embedded SPI (10.5.0_295+) running ekco 0.16.0+.
To check the version of ekco, run:
For older versions, manually create a new envoy pod TLS certificate using the following instructions.
Step 1: Confirm the Envoy Pod TLS Certificate Expiration Date
Run this command to see the current envoy pod certificate expiration date:
The output will look similar to:
Step 2: Renew the Envoy Pod TLS Certificate
(These instructions need only be performed once, regardless of the number of cluster nodes.)
Step 3: Check Kubernetes certificates expiration dates and renew if necessary Follow the steps outlined in How to renew certificates on Kubernetes
ο»Ώ
ο»Ώ
ο»Ώ