Getting kubernetes cluster CA cert
If you want to validate the cluster identity when working with kubectl you'll have to specify the certificate authority cert in your kubeconfig.
yaml
apiVersion: v1
kind: Config
clusters:
- cluster:
certificate-authority-data: abcxyz==
If you don't have it, you can ommit the line to start with and turn off the tls verification.yaml
apiVersion: v1
kind: Config
clusters:
- cluster:
# certificate-authority-data: abcxyz==
insecure-skip-tls-verify: true
This will allow you to fetch the certificate that is stored as a config map (cm) in the cluster, convert it to base64 so you can store it inline.bash
kubectl get cm/kube-root-ca.crt -o json | jq -r .data.\"ca.crt\" | base64 -w0
Requires kubectl with a valid kubeconfig, jq and base64 installedEnter the certificate authority data in your kubeconfig, remove the insecure skip and you are good to go.