Getting kubernetes cluster CA cert

If you want to validate the cluster identity when working with kubectl you'll have to specify the certificate authority cert in your kubeconfig.

yaml
apiVersion: v1
kind: Config
clusters:
- cluster:
    certificate-authority-data: abcxyz==
If you don't have it, you can ommit the line to start with and turn off the tls verification.

yaml
apiVersion: v1
kind: Config
clusters:
- cluster:
    # certificate-authority-data: abcxyz==
    insecure-skip-tls-verify: true
This will allow you to fetch the certificate that is stored as a config map (cm) in the cluster, convert it to base64 so you can store it inline.

bash
kubectl get cm/kube-root-ca.crt -o json | jq -r .data.\"ca.crt\" | base64 -w0
Requires kubectl with a valid kubeconfig, jq and base64 installed

Enter the certificate authority data in your kubeconfig, remove the insecure skip and you are good to go.