Version 1.13. This version is no longer supported. For information about how to upgrade to version 1.14, see Upgrading Anthos on bare metal in the 1.14 documentation. For more information about supported and unsupported versions, see the Version history page in the latest documentation.
This document describes periodic maintenance that is required for your
GKE Enterprise clusters on bare metal.
Rotate certificate authorities
The certificate authorities (CAs) in a cluster are valid for five years, so you
must
rotate your CAs
at least once every five years.
Certificates for cluster components
Cluster components use certificates for authentication. These components
include kube-apiserver, kube-controller-manager, kube-scheduler, etcd and
kubelet. The certificates are valid for 1 year and are renewed during cluster
upgrade.
To prevent the certificates from expiring, you must upgrade your cluster at
least once a year.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-03-05 UTC."],[[["This document outlines the periodic maintenance necessary for GKE Enterprise clusters on bare metal."],["Certificate authorities (CAs) in the cluster have a five-year validity, requiring rotation at least once every five years."],["Cluster components utilize certificates for authentication, which are valid for one year."],["Cluster upgrades renew the component certificates, and must be performed at least once per year."]]],[]]