)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"8dc32194894898f308b54b7e3e2a604213c627ce","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"622dc134_759d1d7c","updated":"2025-12-16 13:14:22.000000000","message":"For Default Duration and Default Renewal Frequency (renew before)\nisn\u0027t this \"roughly\" the numbers\n\n( DOH ... didn\u0027t paste well ... i\u0027ll send in an email )\n\nCertificate                                                                         Default Duration                           Default Renewal Frequency\n                                                                                                                                                         ( or renew-before )\n\n\netcd Root CA certificate                                                    10 years                                                Manual (alarmed within 30 days)                                 \netcd server certificate                                                         1 year                                                   30 days\netcd client certificate                                                          1 year                                                   30 days\nkube-apiserver-etcd-client certificate                             1 year                                                   30 days\n\nKubernetes-root-ca                                                            10 years                                                Manual (alarmed within 30 days)                                                    \nadmin.conf                                                                          1 year                                                   30 days\nsuper-admin.conf                                                              1 year                                                   30 days\ncontroller-manager.conf                                                  1 year                                                   30 days\nscheduler.conf                                                                   1 year                                                   30 days\nkube-apiserver certificate                                               1 year                                                   30 days\nkube-apiserver-kubelet client certificate                      1 year                                                   30 days\nkubelet client certificate                                                   1 year                                                   30 days\nfront-proxy-client                                                              1 year                                                   30 days\nfront-proxy-ca                                                                    10 years                                                Manual (alarmed within 30 days)   \n\nsystem-local-ca                                                              10 years                                                     Manual (alarmed within 30 days)\nsystem-openldap-local-certificate                              90 days (cert-manager)                          15 days (cert-manager)\nsystem-restapi-gui-certificate                                     90 days (cert-manager)                           15 days (cert-manager)\nsystem-registry-local-certificate                                 90 days (cert-manager)                           15 days (cert-manager)\n\noidc-auth-apps-certificate\nOIDC Client and Dex Server CA certificate               \u003c system-local-ca \u003e                                  \u003c system-local-ca \u003e\nOIDC Remote WAD CA Certificate                            NA (not owned by Platform)                  NA (not owned by Platform)\n\nVault Server Certificate                                               90 days (cert-manager)                           15 days (cert-manager)\nVault Root CA certificate                                             \u003c system-local-ca \u003e                                  \u003c system-local-ca \u003e\n\nPortieris Server Certificate                                          90 days (cert-manager)                           15 days (cert-manager)\nPortieris remote registry                                            NA (not owned by Platform)                  NA (not owned by Platform) \n          and notary server CA Certificate\n\nsc-adminep-root-ca-certificate                                    5 years                                                     30 days\nsc-adminep-ca-certificate                                             1 year                                                       30 days\nsc-adminep-certificate                                                  6 months                                                  30 days\n\nssl_ca                                                                              NA (not owned by Platform)                  NA (not owned by Platform)\n\nIPsec certificate                                                            90 days (cert-manager)                           15 days (cert-manager)","commit_id":"57b710178f623b743287b9a3cebebdef1513c03f"}],"doc/source/security/kubernetes/https-access-overview.rst":[{"author":{"_account_id":35312,"name":"Marcelo de Castro Loebens","display_name":"Marcelo Loebens","email":"Marcelo.DeCastroLoebens@windriver.com","username":"mdecastr"},"change_message_id":"c0e8a3275e8928900c3106a0932dcb739ecfea27","unresolved":true,"context_lines":[{"line_number":29,"context_line":"     - System Type"},{"line_number":30,"context_line":"     - Description"},{"line_number":31,"context_line":"     - Auto Created"},{"line_number":32,"context_line":"     - Default Duration"},{"line_number":33,"context_line":"     - Renewal Mechanism"},{"line_number":34,"context_line":"     - Default Renewal Frequency  (or renew-before time)"},{"line_number":35,"context_line":"     - Impact of Certificate Expiry"}],"source_content_type":"text/x-rst","patch_set":1,"id":"aa408908_3dd060e1","line":32,"range":{"start_line":32,"start_character":0,"end_line":32,"end_character":2},"updated":"2025-12-04 15:39:13.000000000","message":"\u0027Default Duration\u0027 and \u0027Default Renewal Frequency\u0027 have no data for any of the certificates.","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"995f3e5aab1686fa5d290e6e741f559601ca33f8","unresolved":false,"context_lines":[{"line_number":29,"context_line":"     - System Type"},{"line_number":30,"context_line":"     - Description"},{"line_number":31,"context_line":"     - Auto Created"},{"line_number":32,"context_line":"     - Default Duration"},{"line_number":33,"context_line":"     - Renewal Mechanism"},{"line_number":34,"context_line":"     - Default Renewal Frequency  (or renew-before time)"},{"line_number":35,"context_line":"     - Impact of Certificate Expiry"}],"source_content_type":"text/x-rst","patch_set":1,"id":"f40d22b2_f5386a39","line":32,"range":{"start_line":32,"start_character":0,"end_line":32,"end_character":2},"in_reply_to":"aa408908_3dd060e1","updated":"2025-12-11 02:03:27.000000000","message":"Acknowledged","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":35312,"name":"Marcelo de Castro Loebens","display_name":"Marcelo Loebens","email":"Marcelo.DeCastroLoebens@windriver.com","username":"mdecastr"},"change_message_id":"c0e8a3275e8928900c3106a0932dcb739ecfea27","unresolved":true,"context_lines":[{"line_number":96,"context_line":"     -"},{"line_number":97,"context_line":"     - auto-renewed by cron job"},{"line_number":98,"context_line":"     -"},{"line_number":99,"context_line":"     - sysadmin locally using kubectl will fail"},{"line_number":100,"context_line":"   * - Cluster Super Admin client certificate / super-admin.conf"},{"line_number":101,"context_line":"     - ALL"},{"line_number":102,"context_line":"     - The client certificate provides access to the kubernetes-super-admin credentials—a break-glass superuser group that bypasses the standard authorization layer (e.g., RBAC). It is reserved for emergency recovery scenarios, such as when RBAC is misconfigured or non-functional."}],"source_content_type":"text/x-rst","patch_set":1,"id":"c9a54907_99639d95","line":99,"range":{"start_line":99,"start_character":7,"end_line":99,"end_character":47},"updated":"2025-12-04 15:39:13.000000000","message":"K8s cluster is not accessible by sysadmin (via kubectl) and platform services, impacting maintenance operations.","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"1c1b8eb01378e95efd4ee95fe6f25c0725f77de9","unresolved":false,"context_lines":[{"line_number":96,"context_line":"     -"},{"line_number":97,"context_line":"     - auto-renewed by cron job"},{"line_number":98,"context_line":"     -"},{"line_number":99,"context_line":"     - sysadmin locally using kubectl will fail"},{"line_number":100,"context_line":"   * - Cluster Super Admin client certificate / super-admin.conf"},{"line_number":101,"context_line":"     - ALL"},{"line_number":102,"context_line":"     - The client certificate provides access to the kubernetes-super-admin credentials—a break-glass superuser group that bypasses the standard authorization layer (e.g., RBAC). It is reserved for emergency recovery scenarios, such as when RBAC is misconfigured or non-functional."}],"source_content_type":"text/x-rst","patch_set":1,"id":"c1ce2094_919f4266","line":99,"range":{"start_line":99,"start_character":7,"end_line":99,"end_character":47},"in_reply_to":"c9a54907_99639d95","updated":"2025-12-08 04:58:29.000000000","message":"Done","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":32841,"name":"Reinildes Oliveira","display_name":"Rei Oliveira","email":"Reinildes.JoseMateusOliveira@windriver.com","username":"rjosemat"},"change_message_id":"9189c3c79d400e2872d80a06a20244675759387c","unresolved":true,"context_lines":[{"line_number":104,"context_line":"     -"},{"line_number":105,"context_line":"     - auto-renewed by cron job"},{"line_number":106,"context_line":"     -"},{"line_number":107,"context_line":"     -"},{"line_number":108,"context_line":"   * - kube-controller-manager client certificate/controller-manager.conf"},{"line_number":109,"context_line":"     - ALL"},{"line_number":110,"context_line":"     - Client certificate used by kube-controller-manager pod to identify itself to kube-apiserver"}],"source_content_type":"text/x-rst","patch_set":1,"id":"b8b1ecf0_c9225abc","line":107,"updated":"2025-12-04 15:08:46.000000000","message":"Impact on the system: Ability to recover cluster in case of RBAC misconfiguration impacted.","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"1c1b8eb01378e95efd4ee95fe6f25c0725f77de9","unresolved":false,"context_lines":[{"line_number":104,"context_line":"     -"},{"line_number":105,"context_line":"     - auto-renewed by cron job"},{"line_number":106,"context_line":"     -"},{"line_number":107,"context_line":"     -"},{"line_number":108,"context_line":"   * - kube-controller-manager client certificate/controller-manager.conf"},{"line_number":109,"context_line":"     - ALL"},{"line_number":110,"context_line":"     - Client certificate used by kube-controller-manager pod to identify itself to kube-apiserver"}],"source_content_type":"text/x-rst","patch_set":1,"id":"f08a22ef_c408130b","line":107,"in_reply_to":"b8b1ecf0_c9225abc","updated":"2025-12-08 04:58:29.000000000","message":"Done","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":32841,"name":"Reinildes Oliveira","display_name":"Rei Oliveira","email":"Reinildes.JoseMateusOliveira@windriver.com","username":"rjosemat"},"change_message_id":"9189c3c79d400e2872d80a06a20244675759387c","unresolved":true,"context_lines":[{"line_number":120,"context_line":"     -"},{"line_number":121,"context_line":"     - auto-renewed by cron job"},{"line_number":122,"context_line":"     -"},{"line_number":123,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":124,"context_line":"   * - kube-apiserver certificate"},{"line_number":125,"context_line":"     - ALL"},{"line_number":126,"context_line":"     - The certificate is used by the kube-apiserver to authenticate itself internally over HTTPS. Internal clients verify this certificate using the Kubernetes root CA. For external clients, the ssl(restapi/gui)/system-restapi-gui-certificate is presented to identify the system\u0027s kube-apiserver. This approach allows external clients to rely solely on the system-local-ca to validate all HTTPS-based endpoints exposed externally."}],"source_content_type":"text/x-rst","patch_set":1,"id":"183e7280_21dbb2e9","line":123,"range":{"start_line":123,"start_character":7,"end_line":123,"end_character":82},"updated":"2025-12-04 15:08:46.000000000","message":"@greg.waines@windriver.com , the kube scheduler certificate impacts the ability to schedule new pods on the node. I think we can say:\n\nPods and workloads currently running will not be affected, but new pods will not be scheduled on the k8s node where the certificate is expired.","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"1c1b8eb01378e95efd4ee95fe6f25c0725f77de9","unresolved":false,"context_lines":[{"line_number":120,"context_line":"     -"},{"line_number":121,"context_line":"     - auto-renewed by cron job"},{"line_number":122,"context_line":"     -"},{"line_number":123,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":124,"context_line":"   * - kube-apiserver certificate"},{"line_number":125,"context_line":"     - ALL"},{"line_number":126,"context_line":"     - The certificate is used by the kube-apiserver to authenticate itself internally over HTTPS. Internal clients verify this certificate using the Kubernetes root CA. For external clients, the ssl(restapi/gui)/system-restapi-gui-certificate is presented to identify the system\u0027s kube-apiserver. This approach allows external clients to rely solely on the system-local-ca to validate all HTTPS-based endpoints exposed externally."}],"source_content_type":"text/x-rst","patch_set":1,"id":"4c57de0c_31af93df","line":123,"range":{"start_line":123,"start_character":7,"end_line":123,"end_character":82},"in_reply_to":"183e7280_21dbb2e9","updated":"2025-12-08 04:58:29.000000000","message":"Done","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":32841,"name":"Reinildes Oliveira","display_name":"Rei Oliveira","email":"Reinildes.JoseMateusOliveira@windriver.com","username":"rjosemat"},"change_message_id":"9189c3c79d400e2872d80a06a20244675759387c","unresolved":true,"context_lines":[{"line_number":128,"context_line":"     -"},{"line_number":129,"context_line":"     - auto-renewed by cron job"},{"line_number":130,"context_line":"     -"},{"line_number":131,"context_line":"     - External HTTPS clients trying to connect to K8s REST APIs will fail"},{"line_number":132,"context_line":"   * - kube-apiserver-kubelet client certificate"},{"line_number":133,"context_line":"     - ALL"},{"line_number":134,"context_line":"     - Kube-apiserver\u0027s client certificate used for communication with kubelet"}],"source_content_type":"text/x-rst","patch_set":1,"id":"f848450a_0cf55cc8","line":131,"range":{"start_line":131,"start_character":7,"end_line":131,"end_character":15},"updated":"2025-12-04 15:08:46.000000000","message":"This needs to be version specific. \nStx master and \u003e stx 11 (2025): Internal clients affected\n\u003c stx 11 (2025): Internal and External clients affected","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"1c1b8eb01378e95efd4ee95fe6f25c0725f77de9","unresolved":false,"context_lines":[{"line_number":128,"context_line":"     -"},{"line_number":129,"context_line":"     - auto-renewed by cron job"},{"line_number":130,"context_line":"     -"},{"line_number":131,"context_line":"     - External HTTPS clients trying to connect to K8s REST APIs will fail"},{"line_number":132,"context_line":"   * - kube-apiserver-kubelet client certificate"},{"line_number":133,"context_line":"     - ALL"},{"line_number":134,"context_line":"     - Kube-apiserver\u0027s client certificate used for communication with kubelet"}],"source_content_type":"text/x-rst","patch_set":1,"id":"c5c20efc_7dca0f89","line":131,"range":{"start_line":131,"start_character":7,"end_line":131,"end_character":15},"in_reply_to":"aee2d3f9_8695c306","updated":"2025-12-08 04:58:29.000000000","message":"Done","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":35312,"name":"Marcelo de Castro Loebens","display_name":"Marcelo Loebens","email":"Marcelo.DeCastroLoebens@windriver.com","username":"mdecastr"},"change_message_id":"c0e8a3275e8928900c3106a0932dcb739ecfea27","unresolved":true,"context_lines":[{"line_number":128,"context_line":"     -"},{"line_number":129,"context_line":"     - auto-renewed by cron job"},{"line_number":130,"context_line":"     -"},{"line_number":131,"context_line":"     - External HTTPS clients trying to connect to K8s REST APIs will fail"},{"line_number":132,"context_line":"   * - kube-apiserver-kubelet client certificate"},{"line_number":133,"context_line":"     - ALL"},{"line_number":134,"context_line":"     - Kube-apiserver\u0027s client certificate used for communication with kubelet"}],"source_content_type":"text/x-rst","patch_set":1,"id":"aee2d3f9_8695c306","line":131,"range":{"start_line":131,"start_character":7,"end_line":131,"end_character":15},"in_reply_to":"f848450a_0cf55cc8","updated":"2025-12-04 15:39:13.000000000","message":"I think we can generalize:\nClients trying to connect to K8s REST APIs will fail.\n\nAlso include this, since some o these internal clients are K8s services:\nK8s cluster is not usable which will likely impact service of K8s workloads.","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":35312,"name":"Marcelo de Castro Loebens","display_name":"Marcelo Loebens","email":"Marcelo.DeCastroLoebens@windriver.com","username":"mdecastr"},"change_message_id":"c0e8a3275e8928900c3106a0932dcb739ecfea27","unresolved":true,"context_lines":[{"line_number":161,"context_line":"     - NOT AUTO-RENEWED; Default expiry is set at 10 years"},{"line_number":162,"context_line":"     -"},{"line_number":163,"context_line":"     - Only K8s Aggregated APIs (example: metrics server API) fail"},{"line_number":164,"context_line":"   * - |prod|"},{"line_number":165,"context_line":"     -"},{"line_number":166,"context_line":"     -"},{"line_number":167,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":1,"id":"fad54e3f_4dce5a8d","line":164,"range":{"start_line":164,"start_character":0,"end_line":164,"end_character":13},"updated":"2025-12-04 15:39:13.000000000","message":"This should be be bold.","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"1c1b8eb01378e95efd4ee95fe6f25c0725f77de9","unresolved":false,"context_lines":[{"line_number":161,"context_line":"     - NOT AUTO-RENEWED; Default expiry is set at 10 years"},{"line_number":162,"context_line":"     -"},{"line_number":163,"context_line":"     - Only K8s Aggregated APIs (example: metrics server API) fail"},{"line_number":164,"context_line":"   * - |prod|"},{"line_number":165,"context_line":"     -"},{"line_number":166,"context_line":"     -"},{"line_number":167,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":1,"id":"8cb38673_82054a9a","line":164,"range":{"start_line":164,"start_character":0,"end_line":164,"end_character":13},"in_reply_to":"fad54e3f_4dce5a8d","updated":"2025-12-08 04:58:29.000000000","message":"Acknowledged","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":32841,"name":"Reinildes Oliveira","display_name":"Rei Oliveira","email":"Reinildes.JoseMateusOliveira@windriver.com","username":"rjosemat"},"change_message_id":"9189c3c79d400e2872d80a06a20244675759387c","unresolved":true,"context_lines":[{"line_number":177,"context_line":"     -"},{"line_number":178,"context_line":"     - NOT AUTO-RENEWED. MUST be renewed via CLI. It is recommended to to use a CA certificate with a long remaining validity (~5-10 years)."},{"line_number":179,"context_line":"     -"},{"line_number":180,"context_line":"     - External HTTPS clients trying to connect to |prod| REST APIs, registry.local, and |OIDC| Client / DEX Server will fail"},{"line_number":181,"context_line":"   * - system-openldap-local-certificate"},{"line_number":182,"context_line":"     - standalone, SystemController"},{"line_number":183,"context_line":"     - Certificate used by OpenLDAP server to identify itself over HTTPS. It is signed by **system-local-ca**. Services such as |SSH|/|SSSD| that access OpenLDAP verify this serving certificate with **system-local-ca**."}],"source_content_type":"text/x-rst","patch_set":1,"id":"47dbfaca_567c1d2f","line":180,"range":{"start_line":180,"start_character":105,"end_line":180,"end_character":115},"updated":"2025-12-04 15:08:46.000000000","message":"Dex server and kube-apiserver. Kube-apiserver if version \u003e stx 11 (2025):\n\n@greg.waines@windriver.com this affects internal clients as well as external clients. Do we want to mention only external ?","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"1527f0a726c79cee288072bb78dc5ec92394a055","unresolved":true,"context_lines":[{"line_number":177,"context_line":"     -"},{"line_number":178,"context_line":"     - NOT AUTO-RENEWED. MUST be renewed via CLI. It is recommended to to use a CA certificate with a long remaining validity (~5-10 years)."},{"line_number":179,"context_line":"     -"},{"line_number":180,"context_line":"     - External HTTPS clients trying to connect to |prod| REST APIs, registry.local, and |OIDC| Client / DEX Server will fail"},{"line_number":181,"context_line":"   * - system-openldap-local-certificate"},{"line_number":182,"context_line":"     - standalone, SystemController"},{"line_number":183,"context_line":"     - Certificate used by OpenLDAP server to identify itself over HTTPS. It is signed by **system-local-ca**. Services such as |SSH|/|SSSD| that access OpenLDAP verify this serving certificate with **system-local-ca**."}],"source_content_type":"text/x-rst","patch_set":1,"id":"4b964db4_d8422094","line":180,"range":{"start_line":180,"start_character":105,"end_line":180,"end_character":115},"in_reply_to":"47dbfaca_567c1d2f","updated":"2025-12-08 12:56:20.000000000","message":"yeah lets only mention external for now","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"27918293d54d4ad8719ac81a41050813090dbb41","unresolved":false,"context_lines":[{"line_number":177,"context_line":"     -"},{"line_number":178,"context_line":"     - NOT AUTO-RENEWED. MUST be renewed via CLI. It is recommended to to use a CA certificate with a long remaining validity (~5-10 years)."},{"line_number":179,"context_line":"     -"},{"line_number":180,"context_line":"     - External HTTPS clients trying to connect to |prod| REST APIs, registry.local, and |OIDC| Client / DEX Server will fail"},{"line_number":181,"context_line":"   * - system-openldap-local-certificate"},{"line_number":182,"context_line":"     - standalone, SystemController"},{"line_number":183,"context_line":"     - Certificate used by OpenLDAP server to identify itself over HTTPS. It is signed by **system-local-ca**. Services such as |SSH|/|SSSD| that access OpenLDAP verify this serving certificate with **system-local-ca**."}],"source_content_type":"text/x-rst","patch_set":1,"id":"449d822a_a8caa29b","line":180,"range":{"start_line":180,"start_character":105,"end_line":180,"end_character":115},"in_reply_to":"4b964db4_d8422094","updated":"2025-12-09 04:01:26.000000000","message":"Done","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":32841,"name":"Reinildes Oliveira","display_name":"Rei Oliveira","email":"Reinildes.JoseMateusOliveira@windriver.com","username":"rjosemat"},"change_message_id":"9189c3c79d400e2872d80a06a20244675759387c","unresolved":true,"context_lines":[{"line_number":194,"context_line":"     -"},{"line_number":195,"context_line":"     - auto-renewed by cert-manager, as long as system-local-ca is valid"},{"line_number":196,"context_line":"     -"},{"line_number":197,"context_line":"     - External HTTPS clients trying to connect to |prod| REST APIs will fail"},{"line_number":198,"context_line":"   * - docker_registry/system-registry-local-certificate"},{"line_number":199,"context_line":"     - ALL"},{"line_number":200,"context_line":"     - Certificate used by Docker distribution server (registry.local ) to identify itself over HTTPS. It is signed by **system-local-ca**. Services such as internal and/or external clients of registry"}],"source_content_type":"text/x-rst","patch_set":1,"id":"5b610a21_ac99b1c3","line":197,"updated":"2025-12-04 15:08:46.000000000","message":"REST api, kube-apiserver, horizon.","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"1c1b8eb01378e95efd4ee95fe6f25c0725f77de9","unresolved":false,"context_lines":[{"line_number":194,"context_line":"     -"},{"line_number":195,"context_line":"     - auto-renewed by cert-manager, as long as system-local-ca is valid"},{"line_number":196,"context_line":"     -"},{"line_number":197,"context_line":"     - External HTTPS clients trying to connect to |prod| REST APIs will fail"},{"line_number":198,"context_line":"   * - docker_registry/system-registry-local-certificate"},{"line_number":199,"context_line":"     - ALL"},{"line_number":200,"context_line":"     - Certificate used by Docker distribution server (registry.local ) to identify itself over HTTPS. It is signed by **system-local-ca**. Services such as internal and/or external clients of registry"}],"source_content_type":"text/x-rst","patch_set":1,"id":"6f02846e_bf1d6afb","line":197,"in_reply_to":"5b610a21_ac99b1c3","updated":"2025-12-08 04:58:29.000000000","message":"Done","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":32841,"name":"Reinildes Oliveira","display_name":"Rei Oliveira","email":"Reinildes.JoseMateusOliveira@windriver.com","username":"rjosemat"},"change_message_id":"9189c3c79d400e2872d80a06a20244675759387c","unresolved":true,"context_lines":[{"line_number":337,"context_line":"     -"},{"line_number":338,"context_line":"     - IPsec certificate is auto-renewed by cron job, as long as system-local-ca is valid"},{"line_number":339,"context_line":"     -"},{"line_number":340,"context_line":"     -"},{"line_number":341,"context_line":""},{"line_number":342,"context_line":"Where:"},{"line_number":343,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"a4c04e27_6c685366","line":340,"updated":"2025-12-04 15:08:46.000000000","message":"Network traffic over management network is interrupted.","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"1c1b8eb01378e95efd4ee95fe6f25c0725f77de9","unresolved":false,"context_lines":[{"line_number":337,"context_line":"     -"},{"line_number":338,"context_line":"     - IPsec certificate is auto-renewed by cron job, as long as system-local-ca is valid"},{"line_number":339,"context_line":"     -"},{"line_number":340,"context_line":"     -"},{"line_number":341,"context_line":""},{"line_number":342,"context_line":"Where:"},{"line_number":343,"context_line":""}],"source_content_type":"text/x-rst","patch_set":1,"id":"b2a503e8_4accb7f1","line":340,"in_reply_to":"a4c04e27_6c685366","updated":"2025-12-08 04:58:29.000000000","message":"Done","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":35312,"name":"Marcelo de Castro Loebens","display_name":"Marcelo Loebens","email":"Marcelo.DeCastroLoebens@windriver.com","username":"mdecastr"},"change_message_id":"c0e8a3275e8928900c3106a0932dcb739ecfea27","unresolved":true,"context_lines":[{"line_number":348,"context_line":"    when expiry date approaches."},{"line_number":349,"context_line":""},{"line_number":350,"context_line":"The specific certificates, and details such as expiration date, that are"},{"line_number":351,"context_line":"present on a |prod| system can be displayed with a local script, :command:`sudo"},{"line_number":352,"context_line":"show-certs.sh`, see :ref:`utility-script-to-display-certificates`."},{"line_number":353,"context_line":""},{"line_number":354,"context_line":"|prod| monitors the installed certificates on the system by raising alarms for"}],"source_content_type":"text/x-rst","patch_set":1,"id":"3ac6bf09_930bf615","line":351,"range":{"start_line":351,"start_character":44,"end_line":351,"end_character":63},"updated":"2025-12-04 15:39:13.000000000","message":"using \u0027system certificate-list\u0027 or a local script","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"1c1b8eb01378e95efd4ee95fe6f25c0725f77de9","unresolved":false,"context_lines":[{"line_number":348,"context_line":"    when expiry date approaches."},{"line_number":349,"context_line":""},{"line_number":350,"context_line":"The specific certificates, and details such as expiration date, that are"},{"line_number":351,"context_line":"present on a |prod| system can be displayed with a local script, :command:`sudo"},{"line_number":352,"context_line":"show-certs.sh`, see :ref:`utility-script-to-display-certificates`."},{"line_number":353,"context_line":""},{"line_number":354,"context_line":"|prod| monitors the installed certificates on the system by raising alarms for"}],"source_content_type":"text/x-rst","patch_set":1,"id":"537cb0bf_4109dd59","line":351,"range":{"start_line":351,"start_character":44,"end_line":351,"end_character":63},"in_reply_to":"3ac6bf09_930bf615","updated":"2025-12-08 04:58:29.000000000","message":"Done","commit_id":"e6ee8318811d5a9eb6526b2565c0d20eee511f85"},{"author":{"_account_id":32841,"name":"Reinildes Oliveira","display_name":"Rei Oliveira","email":"Reinildes.JoseMateusOliveira@windriver.com","username":"rjosemat"},"change_message_id":"8c9da07f9779c90d46db65ceb58c5e4694dd6b7a","unresolved":true,"context_lines":[{"line_number":31,"context_line":"     - Auto Created"},{"line_number":32,"context_line":"     - Default Duration"},{"line_number":33,"context_line":"     - Renewal Mechanism"},{"line_number":34,"context_line":"     - Default Renewal Frequency  (or renew-before time)"},{"line_number":35,"context_line":"     - Impact of Certificate Expiry"},{"line_number":36,"context_line":"   * - **Etcd:**"},{"line_number":37,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":3,"id":"c18e64a6_18a2dd5c","line":34,"range":{"start_line":34,"start_character":7,"end_line":34,"end_character":56},"updated":"2026-01-13 15:45:13.000000000","message":"I don\u0027t understand what this field means. \"Default Renewal Frequency\" is too similar sounding to \"Default Duration\".\n\nIs this the Renew Before time ? If so, then I think naming it \"Renewal Period\" or \"Renewal window\" is more appropriate. Or simply \"Renew Before Expiration Time\"\n\n@Marcelo.DeCastroLoebens@windriver.com / @greg.waines@windriver.com / @ngairangbam.mili@windriver.com","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":31,"context_line":"     - Auto Created"},{"line_number":32,"context_line":"     - Default Duration"},{"line_number":33,"context_line":"     - Renewal Mechanism"},{"line_number":34,"context_line":"     - Default Renewal Frequency  (or renew-before time)"},{"line_number":35,"context_line":"     - Impact of Certificate Expiry"},{"line_number":36,"context_line":"   * - **Etcd:**"},{"line_number":37,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":3,"id":"61164a49_ef38fe67","line":34,"range":{"start_line":34,"start_character":7,"end_line":34,"end_character":56},"in_reply_to":"03778282_9926c1d5","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":31,"context_line":"     - Auto Created"},{"line_number":32,"context_line":"     - Default Duration"},{"line_number":33,"context_line":"     - Renewal Mechanism"},{"line_number":34,"context_line":"     - Default Renewal Frequency  (or renew-before time)"},{"line_number":35,"context_line":"     - Impact of Certificate Expiry"},{"line_number":36,"context_line":"   * - **Etcd:**"},{"line_number":37,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":3,"id":"03778282_9926c1d5","line":34,"range":{"start_line":34,"start_character":7,"end_line":34,"end_character":56},"in_reply_to":"c18e64a6_18a2dd5c","updated":"2026-01-14 12:00:29.000000000","message":"Yeah I agree ... let\u0027s change it to \u0027Renew-before\u0027 time.","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":49,"context_line":"     - NOT AUTO-RENEWED; Default expiry is set at 10 years. When an override is"},{"line_number":50,"context_line":"       provided, it is recommended to to use a CA certificate with a long"},{"line_number":51,"context_line":"       remaining validity (~5-10 years)."},{"line_number":52,"context_line":"     - Manual (alarmed within 30 days)"},{"line_number":53,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":54,"context_line":"   * - etcd server certificate"},{"line_number":55,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"bd2ca9f8_f23d2265","line":52,"range":{"start_line":52,"start_character":23,"end_line":52,"end_character":37},"updated":"2026-01-14 12:00:29.000000000","message":"within 30 days of expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":49,"context_line":"     - NOT AUTO-RENEWED; Default expiry is set at 10 years. When an override is"},{"line_number":50,"context_line":"       provided, it is recommended to to use a CA certificate with a long"},{"line_number":51,"context_line":"       remaining validity (~5-10 years)."},{"line_number":52,"context_line":"     - Manual (alarmed within 30 days)"},{"line_number":53,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":54,"context_line":"   * - etcd server certificate"},{"line_number":55,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"cd572893_5e02b050","line":52,"range":{"start_line":52,"start_character":23,"end_line":52,"end_character":37},"in_reply_to":"bd2ca9f8_f23d2265","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":59,"context_line":"     - Yes"},{"line_number":60,"context_line":"     - 1 year"},{"line_number":61,"context_line":"     - auto-renewed by cron job"},{"line_number":62,"context_line":"     - 30 days"},{"line_number":63,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":64,"context_line":"   * - etcd client certificate"},{"line_number":65,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"3442a506_b45c30a9","line":62,"range":{"start_line":62,"start_character":7,"end_line":62,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"30 days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":59,"context_line":"     - Yes"},{"line_number":60,"context_line":"     - 1 year"},{"line_number":61,"context_line":"     - auto-renewed by cron job"},{"line_number":62,"context_line":"     - 30 days"},{"line_number":63,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":64,"context_line":"   * - etcd client certificate"},{"line_number":65,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"a5e77a2b_25a6d7e8","line":62,"range":{"start_line":62,"start_character":7,"end_line":62,"end_character":14},"in_reply_to":"3442a506_b45c30a9","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":67,"context_line":"     - Yes"},{"line_number":68,"context_line":"     - 1 year"},{"line_number":69,"context_line":"     - auto-renewed by cron job"},{"line_number":70,"context_line":"     - 30 days"},{"line_number":71,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":72,"context_line":"   * - kube-apiserver-etcd-client certificate"},{"line_number":73,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"a089e30b_5779d942","line":70,"range":{"start_line":70,"start_character":7,"end_line":70,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"30 days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":67,"context_line":"     - Yes"},{"line_number":68,"context_line":"     - 1 year"},{"line_number":69,"context_line":"     - auto-renewed by cron job"},{"line_number":70,"context_line":"     - 30 days"},{"line_number":71,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":72,"context_line":"   * - kube-apiserver-etcd-client certificate"},{"line_number":73,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"c3124cad_3554c332","line":70,"range":{"start_line":70,"start_character":7,"end_line":70,"end_character":14},"in_reply_to":"a089e30b_5779d942","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":75,"context_line":"     - Yes"},{"line_number":76,"context_line":"     - 1 year"},{"line_number":77,"context_line":"     - auto-renewed by cron job"},{"line_number":78,"context_line":"     - 30 days"},{"line_number":79,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":80,"context_line":"   * - **Kubernetes:**"},{"line_number":81,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":3,"id":"2a456964_a5310d1b","line":78,"range":{"start_line":78,"start_character":7,"end_line":78,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"30 days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":75,"context_line":"     - Yes"},{"line_number":76,"context_line":"     - 1 year"},{"line_number":77,"context_line":"     - auto-renewed by cron job"},{"line_number":78,"context_line":"     - 30 days"},{"line_number":79,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":80,"context_line":"   * - **Kubernetes:**"},{"line_number":81,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":3,"id":"18e76aa4_073ac19b","line":78,"range":{"start_line":78,"start_character":7,"end_line":78,"end_character":14},"in_reply_to":"2a456964_a5310d1b","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":97,"context_line":"     - NOT AUTO-RENEWED; Default expiry is set at 10 years; MUST be renewed via"},{"line_number":98,"context_line":"       CLI. When an override is provided, it is recommended to to use a CA"},{"line_number":99,"context_line":"       certificate with a long remaining validity (~5-10 years)."},{"line_number":100,"context_line":"     - Manual (alarmed within 30 days)"},{"line_number":101,"context_line":"     - K8s cluster is not usable which will likely impact service of K8S workloads"},{"line_number":102,"context_line":"   * - Cluster Admin client certificate used by kubectl / admin.conf"},{"line_number":103,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"6c9eb305_df0eeadb","line":100,"range":{"start_line":100,"start_character":23,"end_line":100,"end_character":38},"updated":"2026-01-14 12:00:29.000000000","message":"within 30 days of expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":97,"context_line":"     - NOT AUTO-RENEWED; Default expiry is set at 10 years; MUST be renewed via"},{"line_number":98,"context_line":"       CLI. When an override is provided, it is recommended to to use a CA"},{"line_number":99,"context_line":"       certificate with a long remaining validity (~5-10 years)."},{"line_number":100,"context_line":"     - Manual (alarmed within 30 days)"},{"line_number":101,"context_line":"     - K8s cluster is not usable which will likely impact service of K8S workloads"},{"line_number":102,"context_line":"   * - Cluster Admin client certificate used by kubectl / admin.conf"},{"line_number":103,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"8840acfc_4b39412d","line":100,"range":{"start_line":100,"start_character":23,"end_line":100,"end_character":38},"in_reply_to":"6c9eb305_df0eeadb","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":107,"context_line":"     - Yes"},{"line_number":108,"context_line":"     - 1 year"},{"line_number":109,"context_line":"     - auto-renewed by cron job"},{"line_number":110,"context_line":"     - 30 days"},{"line_number":111,"context_line":"     - K8s cluster is not accessible by sysadmin (via kubectl) and platform"},{"line_number":112,"context_line":"       services, impacting maintenance operations."},{"line_number":113,"context_line":"   * - Cluster Super Admin client certificate / super-admin.conf"}],"source_content_type":"text/x-rst","patch_set":3,"id":"4bd90fe7_83a1c454","line":110,"range":{"start_line":110,"start_character":7,"end_line":110,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"30 days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":107,"context_line":"     - Yes"},{"line_number":108,"context_line":"     - 1 year"},{"line_number":109,"context_line":"     - auto-renewed by cron job"},{"line_number":110,"context_line":"     - 30 days"},{"line_number":111,"context_line":"     - K8s cluster is not accessible by sysadmin (via kubectl) and platform"},{"line_number":112,"context_line":"       services, impacting maintenance operations."},{"line_number":113,"context_line":"   * - Cluster Super Admin client certificate / super-admin.conf"}],"source_content_type":"text/x-rst","patch_set":3,"id":"5c595f4a_d506c81b","line":110,"range":{"start_line":110,"start_character":7,"end_line":110,"end_character":14},"in_reply_to":"4bd90fe7_83a1c454","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":119,"context_line":"     - Yes"},{"line_number":120,"context_line":"     - 1 year"},{"line_number":121,"context_line":"     - auto-renewed by cron job"},{"line_number":122,"context_line":"     - 30 days"},{"line_number":123,"context_line":"     - Ability to recover cluster in case of |RBAC| misconfiguration impacted."},{"line_number":124,"context_line":"   * - kube-controller-manager client certificate/controller-manager.conf"},{"line_number":125,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"103bb3b2_d6b289bd","line":122,"range":{"start_line":122,"start_character":7,"end_line":122,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"30 days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":119,"context_line":"     - Yes"},{"line_number":120,"context_line":"     - 1 year"},{"line_number":121,"context_line":"     - auto-renewed by cron job"},{"line_number":122,"context_line":"     - 30 days"},{"line_number":123,"context_line":"     - Ability to recover cluster in case of |RBAC| misconfiguration impacted."},{"line_number":124,"context_line":"   * - kube-controller-manager client certificate/controller-manager.conf"},{"line_number":125,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"0eb9a7bb_d1529100","line":122,"range":{"start_line":122,"start_character":7,"end_line":122,"end_character":14},"in_reply_to":"103bb3b2_d6b289bd","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":127,"context_line":"     - Yes"},{"line_number":128,"context_line":"     - 1 year"},{"line_number":129,"context_line":"     - auto-renewed by cron job"},{"line_number":130,"context_line":"     - 30 days"},{"line_number":131,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":132,"context_line":"   * - kube-scheduler client certificate / scheduler.conf"},{"line_number":133,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"a2cff327_22be0a8f","line":130,"range":{"start_line":130,"start_character":7,"end_line":130,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"30 days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":127,"context_line":"     - Yes"},{"line_number":128,"context_line":"     - 1 year"},{"line_number":129,"context_line":"     - auto-renewed by cron job"},{"line_number":130,"context_line":"     - 30 days"},{"line_number":131,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":132,"context_line":"   * - kube-scheduler client certificate / scheduler.conf"},{"line_number":133,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"0fbc3031_44fcdae9","line":130,"range":{"start_line":130,"start_character":7,"end_line":130,"end_character":14},"in_reply_to":"a2cff327_22be0a8f","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":135,"context_line":"     - Yes"},{"line_number":136,"context_line":"     - 1 year"},{"line_number":137,"context_line":"     - auto-renewed by cron job"},{"line_number":138,"context_line":"     - 30 days"},{"line_number":139,"context_line":"     - The currently running pods and workloads will not be affected, however"},{"line_number":140,"context_line":"       new pods will not be scheduled on the k8s node where the certificate has"},{"line_number":141,"context_line":"       expired"}],"source_content_type":"text/x-rst","patch_set":3,"id":"86ee67d3_4c60564d","line":138,"range":{"start_line":138,"start_character":7,"end_line":138,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"30 days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":135,"context_line":"     - Yes"},{"line_number":136,"context_line":"     - 1 year"},{"line_number":137,"context_line":"     - auto-renewed by cron job"},{"line_number":138,"context_line":"     - 30 days"},{"line_number":139,"context_line":"     - The currently running pods and workloads will not be affected, however"},{"line_number":140,"context_line":"       new pods will not be scheduled on the k8s node where the certificate has"},{"line_number":141,"context_line":"       expired"}],"source_content_type":"text/x-rst","patch_set":3,"id":"5b2afffc_ce435439","line":138,"range":{"start_line":138,"start_character":7,"end_line":138,"end_character":14},"in_reply_to":"86ee67d3_4c60564d","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":151,"context_line":"     - Yes"},{"line_number":152,"context_line":"     - 1 year"},{"line_number":153,"context_line":"     - auto-renewed by cron job"},{"line_number":154,"context_line":"     - 30 days"},{"line_number":155,"context_line":"     - Clients trying to connect to K8s REST APIs will fail. As some of"},{"line_number":156,"context_line":"       these internal clients are K8s services, K8s cluster is not usable which"},{"line_number":157,"context_line":"       will likely impact service of K8s workloads"}],"source_content_type":"text/x-rst","patch_set":3,"id":"84643706_391850e3","line":154,"range":{"start_line":154,"start_character":7,"end_line":154,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"30 days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":151,"context_line":"     - Yes"},{"line_number":152,"context_line":"     - 1 year"},{"line_number":153,"context_line":"     - auto-renewed by cron job"},{"line_number":154,"context_line":"     - 30 days"},{"line_number":155,"context_line":"     - Clients trying to connect to K8s REST APIs will fail. As some of"},{"line_number":156,"context_line":"       these internal clients are K8s services, K8s cluster is not usable which"},{"line_number":157,"context_line":"       will likely impact service of K8s workloads"}],"source_content_type":"text/x-rst","patch_set":3,"id":"fbd43830_4d422f1e","line":154,"range":{"start_line":154,"start_character":7,"end_line":154,"end_character":14},"in_reply_to":"84643706_391850e3","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":161,"context_line":"     - Yes"},{"line_number":162,"context_line":"     - 1 year"},{"line_number":163,"context_line":"     - auto-renewed by cron job"},{"line_number":164,"context_line":"     - 30 days"},{"line_number":165,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":166,"context_line":"   * - kubelet client certificate"},{"line_number":167,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"f016b8e9_430c37f1","line":164,"range":{"start_line":164,"start_character":7,"end_line":164,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"30 days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":161,"context_line":"     - Yes"},{"line_number":162,"context_line":"     - 1 year"},{"line_number":163,"context_line":"     - auto-renewed by cron job"},{"line_number":164,"context_line":"     - 30 days"},{"line_number":165,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":166,"context_line":"   * - kubelet client certificate"},{"line_number":167,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"b9e7874d_36dd3084","line":164,"range":{"start_line":164,"start_character":7,"end_line":164,"end_character":14},"in_reply_to":"f016b8e9_430c37f1","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":169,"context_line":"     - Yes"},{"line_number":170,"context_line":"     - 1 year"},{"line_number":171,"context_line":"     - auto-renewed by kubelet. Feature enabled by default"},{"line_number":172,"context_line":"     - 30 days"},{"line_number":173,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":174,"context_line":"   * - front-proxy-client"},{"line_number":175,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"043f0639_a8c3a04f","line":172,"range":{"start_line":172,"start_character":7,"end_line":172,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"30 days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":169,"context_line":"     - Yes"},{"line_number":170,"context_line":"     - 1 year"},{"line_number":171,"context_line":"     - auto-renewed by kubelet. Feature enabled by default"},{"line_number":172,"context_line":"     - 30 days"},{"line_number":173,"context_line":"     - K8s cluster is not usable which will likely impact service of K8s workloads"},{"line_number":174,"context_line":"   * - front-proxy-client"},{"line_number":175,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"f7b622ce_99ed17fc","line":172,"range":{"start_line":172,"start_character":7,"end_line":172,"end_character":14},"in_reply_to":"043f0639_a8c3a04f","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":179,"context_line":"     - Yes"},{"line_number":180,"context_line":"     - 1 year"},{"line_number":181,"context_line":"     - auto-renewed by cron job"},{"line_number":182,"context_line":"     - 30 days"},{"line_number":183,"context_line":"     - Only K8s Aggregated APIs (example: metrics server API) fail"},{"line_number":184,"context_line":"   * - front-proxy-ca"},{"line_number":185,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"2b5081e9_10a0e8d7","line":182,"range":{"start_line":182,"start_character":7,"end_line":182,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"30 days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":179,"context_line":"     - Yes"},{"line_number":180,"context_line":"     - 1 year"},{"line_number":181,"context_line":"     - auto-renewed by cron job"},{"line_number":182,"context_line":"     - 30 days"},{"line_number":183,"context_line":"     - Only K8s Aggregated APIs (example: metrics server API) fail"},{"line_number":184,"context_line":"   * - front-proxy-ca"},{"line_number":185,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"1f9f8a4c_e2319a35","line":182,"range":{"start_line":182,"start_character":7,"end_line":182,"end_character":14},"in_reply_to":"2b5081e9_10a0e8d7","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":187,"context_line":"     - Yes"},{"line_number":188,"context_line":"     - 10 years"},{"line_number":189,"context_line":"     - NOT AUTO-RENEWED; Default expiry is set at 10 years"},{"line_number":190,"context_line":"     - Manual (alarmed within 30 days)"},{"line_number":191,"context_line":"     - Only K8s Aggregated APIs (example: metrics server API) fail"},{"line_number":192,"context_line":"   * - |prod|"},{"line_number":193,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":3,"id":"143b6611_eadecad5","line":190,"range":{"start_line":190,"start_character":23,"end_line":190,"end_character":37},"updated":"2026-01-14 12:00:29.000000000","message":"within 30 days of expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":187,"context_line":"     - Yes"},{"line_number":188,"context_line":"     - 10 years"},{"line_number":189,"context_line":"     - NOT AUTO-RENEWED; Default expiry is set at 10 years"},{"line_number":190,"context_line":"     - Manual (alarmed within 30 days)"},{"line_number":191,"context_line":"     - Only K8s Aggregated APIs (example: metrics server API) fail"},{"line_number":192,"context_line":"   * - |prod|"},{"line_number":193,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":3,"id":"c84a710f_987547a3","line":190,"range":{"start_line":190,"start_character":23,"end_line":190,"end_character":37},"in_reply_to":"143b6611_eadecad5","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":189,"context_line":"     - NOT AUTO-RENEWED; Default expiry is set at 10 years"},{"line_number":190,"context_line":"     - Manual (alarmed within 30 days)"},{"line_number":191,"context_line":"     - Only K8s Aggregated APIs (example: metrics server API) fail"},{"line_number":192,"context_line":"   * - |prod|"},{"line_number":193,"context_line":"     -"},{"line_number":194,"context_line":"     -"},{"line_number":195,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":3,"id":"4cbb2c38_2638281f","line":192,"range":{"start_line":192,"start_character":0,"end_line":192,"end_character":13},"updated":"2026-01-14 12:00:29.000000000","message":"can you bold this \ne.g.\n\n**|prod|**","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"890ca7219eaf5f18e3c501be3e65231e25b2bbca","unresolved":false,"context_lines":[{"line_number":189,"context_line":"     - NOT AUTO-RENEWED; Default expiry is set at 10 years"},{"line_number":190,"context_line":"     - Manual (alarmed within 30 days)"},{"line_number":191,"context_line":"     - Only K8s Aggregated APIs (example: metrics server API) fail"},{"line_number":192,"context_line":"   * - |prod|"},{"line_number":193,"context_line":"     -"},{"line_number":194,"context_line":"     -"},{"line_number":195,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":3,"id":"aee97851_6c180028","line":192,"range":{"start_line":192,"start_character":0,"end_line":192,"end_character":13},"in_reply_to":"2fdb48b6_6cee1dce","updated":"2026-01-14 13:58:40.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":true,"context_lines":[{"line_number":189,"context_line":"     - NOT AUTO-RENEWED; Default expiry is set at 10 years"},{"line_number":190,"context_line":"     - Manual (alarmed within 30 days)"},{"line_number":191,"context_line":"     - Only K8s Aggregated APIs (example: metrics server API) fail"},{"line_number":192,"context_line":"   * - |prod|"},{"line_number":193,"context_line":"     -"},{"line_number":194,"context_line":"     -"},{"line_number":195,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":3,"id":"2fdb48b6_6cee1dce","line":192,"range":{"start_line":192,"start_character":0,"end_line":192,"end_character":13},"in_reply_to":"4cbb2c38_2638281f","updated":"2026-01-14 13:58:28.000000000","message":"Acknowledged. Will work on this.","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":211,"context_line":"     - 10 years"},{"line_number":212,"context_line":"     - NOT AUTO-RENEWED. MUST be renewed via CLI. It is recommended to to use a"},{"line_number":213,"context_line":"       CA certificate with a long remaining validity (~5-10 years)."},{"line_number":214,"context_line":"     - Manual (alarmed within 30 days)"},{"line_number":215,"context_line":"     - External HTTPS clients trying to connect to |prod| REST APIs,"},{"line_number":216,"context_line":"       registry.local, and |OIDC| Client / DEX Server will fail"},{"line_number":217,"context_line":"   * - system-openldap-local-certificate"}],"source_content_type":"text/x-rst","patch_set":3,"id":"9c1ffb68_d3ec8eff","line":214,"range":{"start_line":214,"start_character":23,"end_line":214,"end_character":37},"updated":"2026-01-14 12:00:29.000000000","message":"within 30 days of expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":211,"context_line":"     - 10 years"},{"line_number":212,"context_line":"     - NOT AUTO-RENEWED. MUST be renewed via CLI. It is recommended to to use a"},{"line_number":213,"context_line":"       CA certificate with a long remaining validity (~5-10 years)."},{"line_number":214,"context_line":"     - Manual (alarmed within 30 days)"},{"line_number":215,"context_line":"     - External HTTPS clients trying to connect to |prod| REST APIs,"},{"line_number":216,"context_line":"       registry.local, and |OIDC| Client / DEX Server will fail"},{"line_number":217,"context_line":"   * - system-openldap-local-certificate"}],"source_content_type":"text/x-rst","patch_set":3,"id":"8b200f42_49fd5bba","line":214,"range":{"start_line":214,"start_character":23,"end_line":214,"end_character":37},"in_reply_to":"9c1ffb68_d3ec8eff","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":222,"context_line":"     - Yes"},{"line_number":223,"context_line":"     - 90 days (cert-manager)"},{"line_number":224,"context_line":"     - auto-renewed by cert-manager, as long as system-local-ca is valid"},{"line_number":225,"context_line":"     - 15 days (cert-manager)"},{"line_number":226,"context_line":"     - Authentication of |prod| local |LDAP| user IDs will fail"},{"line_number":227,"context_line":"   * - ssl(restapi/gui)/system-restapi-gui-certificate"},{"line_number":228,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"f287ae72_0bf28981","line":225,"range":{"start_line":225,"start_character":10,"end_line":225,"end_character":15},"updated":"2026-01-14 12:00:29.000000000","message":"days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":222,"context_line":"     - Yes"},{"line_number":223,"context_line":"     - 90 days (cert-manager)"},{"line_number":224,"context_line":"     - auto-renewed by cert-manager, as long as system-local-ca is valid"},{"line_number":225,"context_line":"     - 15 days (cert-manager)"},{"line_number":226,"context_line":"     - Authentication of |prod| local |LDAP| user IDs will fail"},{"line_number":227,"context_line":"   * - ssl(restapi/gui)/system-restapi-gui-certificate"},{"line_number":228,"context_line":"     - ALL"}],"source_content_type":"text/x-rst","patch_set":3,"id":"1f04892d_29e5c5b1","line":225,"range":{"start_line":225,"start_character":10,"end_line":225,"end_character":15},"in_reply_to":"f287ae72_0bf28981","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":235,"context_line":"     - Yes"},{"line_number":236,"context_line":"     - 90 days (cert-manager)"},{"line_number":237,"context_line":"     - auto-renewed by cert-manager, as long as system-local-ca is valid"},{"line_number":238,"context_line":"     - 15 days (cert-manager)"},{"line_number":239,"context_line":"     - External HTTPS clients trying to connect to |prod| REST APIs,"},{"line_number":240,"context_line":"       kube-apiserver, and horizon will fail"},{"line_number":241,"context_line":"   * - docker_registry/system-registry-local-certificate"}],"source_content_type":"text/x-rst","patch_set":3,"id":"1850595d_beb7d61d","line":238,"range":{"start_line":238,"start_character":10,"end_line":238,"end_character":15},"updated":"2026-01-14 12:00:29.000000000","message":"days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":235,"context_line":"     - Yes"},{"line_number":236,"context_line":"     - 90 days (cert-manager)"},{"line_number":237,"context_line":"     - auto-renewed by cert-manager, as long as system-local-ca is valid"},{"line_number":238,"context_line":"     - 15 days (cert-manager)"},{"line_number":239,"context_line":"     - External HTTPS clients trying to connect to |prod| REST APIs,"},{"line_number":240,"context_line":"       kube-apiserver, and horizon will fail"},{"line_number":241,"context_line":"   * - docker_registry/system-registry-local-certificate"}],"source_content_type":"text/x-rst","patch_set":3,"id":"7cbcced1_8d869ce8","line":238,"range":{"start_line":238,"start_character":10,"end_line":238,"end_character":15},"in_reply_to":"1850595d_beb7d61d","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":248,"context_line":"     - Yes"},{"line_number":249,"context_line":"     - 90 days (cert-manager)"},{"line_number":250,"context_line":"     - auto-renewed by cert-manager, as long as system-local-ca is valid"},{"line_number":251,"context_line":"     - 15 days (cert-manager)"},{"line_number":252,"context_line":"     - External HTTPS clients trying to connect to registry.local will fail"},{"line_number":253,"context_line":"   * - **OIDC:**"},{"line_number":254,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":3,"id":"59dff205_cbf9b0cf","line":251,"range":{"start_line":251,"start_character":10,"end_line":251,"end_character":15},"updated":"2026-01-14 12:00:29.000000000","message":"days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":248,"context_line":"     - Yes"},{"line_number":249,"context_line":"     - 90 days (cert-manager)"},{"line_number":250,"context_line":"     - auto-renewed by cert-manager, as long as system-local-ca is valid"},{"line_number":251,"context_line":"     - 15 days (cert-manager)"},{"line_number":252,"context_line":"     - External HTTPS clients trying to connect to registry.local will fail"},{"line_number":253,"context_line":"   * - **OIDC:**"},{"line_number":254,"context_line":"     -"}],"source_content_type":"text/x-rst","patch_set":3,"id":"f09dfa04_f75e428a","line":251,"range":{"start_line":251,"start_character":10,"end_line":251,"end_character":15},"in_reply_to":"59dff205_cbf9b0cf","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":309,"context_line":"     - Yes"},{"line_number":310,"context_line":"     - 90 days (cert-manager) "},{"line_number":311,"context_line":"     - NOT AUTO-RENEWED; MUST be renewed via CLI."},{"line_number":312,"context_line":"     - 15 days (cert-manager)"},{"line_number":313,"context_line":"     - Pod workloads’ interactions with Vault server will fail"},{"line_number":314,"context_line":"   * - Vault Root CA certificate"},{"line_number":315,"context_line":"     - Optional, but typically standalone, subclouds"}],"source_content_type":"text/x-rst","patch_set":3,"id":"9fb5850b_cc989647","line":312,"range":{"start_line":312,"start_character":10,"end_line":312,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":309,"context_line":"     - Yes"},{"line_number":310,"context_line":"     - 90 days (cert-manager) "},{"line_number":311,"context_line":"     - NOT AUTO-RENEWED; MUST be renewed via CLI."},{"line_number":312,"context_line":"     - 15 days (cert-manager)"},{"line_number":313,"context_line":"     - Pod workloads’ interactions with Vault server will fail"},{"line_number":314,"context_line":"   * - Vault Root CA certificate"},{"line_number":315,"context_line":"     - Optional, but typically standalone, subclouds"}],"source_content_type":"text/x-rst","patch_set":3,"id":"a108f95c_b88eb9a2","line":312,"range":{"start_line":312,"start_character":10,"end_line":312,"end_character":14},"in_reply_to":"9fb5850b_cc989647","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":339,"context_line":"     - 90 days (cert-manager)"},{"line_number":340,"context_line":"     - Auto renewed by cert-manager; BUT CUSTOMER MUST restart Portieris after"},{"line_number":341,"context_line":"       the certificate is renewed"},{"line_number":342,"context_line":"     - 15 days (cert-manager)"},{"line_number":343,"context_line":"     - ALL new pods will likely fail because they will not be able to validate"},{"line_number":344,"context_line":"       their authorization to pull their container image from the registry"},{"line_number":345,"context_line":"   * - Portieris remote registry and notary server CA Certificate"}],"source_content_type":"text/x-rst","patch_set":3,"id":"8e5f3a78_2a4cda32","line":342,"range":{"start_line":342,"start_character":10,"end_line":342,"end_character":15},"updated":"2026-01-14 12:00:29.000000000","message":"days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":339,"context_line":"     - 90 days (cert-manager)"},{"line_number":340,"context_line":"     - Auto renewed by cert-manager; BUT CUSTOMER MUST restart Portieris after"},{"line_number":341,"context_line":"       the certificate is renewed"},{"line_number":342,"context_line":"     - 15 days (cert-manager)"},{"line_number":343,"context_line":"     - ALL new pods will likely fail because they will not be able to validate"},{"line_number":344,"context_line":"       their authorization to pull their container image from the registry"},{"line_number":345,"context_line":"   * - Portieris remote registry and notary server CA Certificate"}],"source_content_type":"text/x-rst","patch_set":3,"id":"a4140a4e_a36b208a","line":342,"range":{"start_line":342,"start_character":10,"end_line":342,"end_character":15},"in_reply_to":"8e5f3a78_2a4cda32","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":370,"context_line":"     - Yes"},{"line_number":371,"context_line":"     - 5 years"},{"line_number":372,"context_line":"     - auto-renewed by cert-manager"},{"line_number":373,"context_line":"     - 30 days"},{"line_number":374,"context_line":"     - SystemController to subcloud communication will fail. Subcloud will"},{"line_number":375,"context_line":"       become unmanageable from SystemController"},{"line_number":376,"context_line":"   * - DC-AdminEp-InterCA / \u003cuuid\u003e-adminep-ca-certificate /"}],"source_content_type":"text/x-rst","patch_set":3,"id":"8ea50ab2_c4f3c50e","line":373,"range":{"start_line":373,"start_character":10,"end_line":373,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":370,"context_line":"     - Yes"},{"line_number":371,"context_line":"     - 5 years"},{"line_number":372,"context_line":"     - auto-renewed by cert-manager"},{"line_number":373,"context_line":"     - 30 days"},{"line_number":374,"context_line":"     - SystemController to subcloud communication will fail. Subcloud will"},{"line_number":375,"context_line":"       become unmanageable from SystemController"},{"line_number":376,"context_line":"   * - DC-AdminEp-InterCA / \u003cuuid\u003e-adminep-ca-certificate /"}],"source_content_type":"text/x-rst","patch_set":3,"id":"ccdda81f_d0c3204d","line":373,"range":{"start_line":373,"start_character":10,"end_line":373,"end_character":14},"in_reply_to":"8ea50ab2_c4f3c50e","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":381,"context_line":"     - Yes"},{"line_number":382,"context_line":"     - 1 year"},{"line_number":383,"context_line":"     - auto-renewed by cert-manager, as long as DC-AdminEp-RootCA is valid"},{"line_number":384,"context_line":"     - 30 days"},{"line_number":385,"context_line":"     - SystemController to subcloud communication will fail. Subcloud will"},{"line_number":386,"context_line":"       become unmanageable from SystemController"},{"line_number":387,"context_line":"   * - DC-AdminEp-Server / dc-adminep-certificate / sc-adminep-certificate"}],"source_content_type":"text/x-rst","patch_set":3,"id":"0ec7c992_e1b85fa7","line":384,"range":{"start_line":384,"start_character":10,"end_line":384,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":381,"context_line":"     - Yes"},{"line_number":382,"context_line":"     - 1 year"},{"line_number":383,"context_line":"     - auto-renewed by cert-manager, as long as DC-AdminEp-RootCA is valid"},{"line_number":384,"context_line":"     - 30 days"},{"line_number":385,"context_line":"     - SystemController to subcloud communication will fail. Subcloud will"},{"line_number":386,"context_line":"       become unmanageable from SystemController"},{"line_number":387,"context_line":"   * - DC-AdminEp-Server / dc-adminep-certificate / sc-adminep-certificate"}],"source_content_type":"text/x-rst","patch_set":3,"id":"a96185db_a7ee5565","line":384,"range":{"start_line":384,"start_character":10,"end_line":384,"end_character":14},"in_reply_to":"0ec7c992_e1b85fa7","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":393,"context_line":"     - Yes"},{"line_number":394,"context_line":"     - 6 months"},{"line_number":395,"context_line":"     - auto-renewed by cert-manager, as long as sc-adminep-ca-certificate is valid"},{"line_number":396,"context_line":"     - 30 days"},{"line_number":397,"context_line":"     - SystemController to subcloud communication will fail. Subcloud will"},{"line_number":398,"context_line":"       become unmanageable from SystemController"},{"line_number":399,"context_line":"   * - **System trusted CA Certificates (ssl_ca)**"}],"source_content_type":"text/x-rst","patch_set":3,"id":"078d168f_83ba878c","line":396,"range":{"start_line":396,"start_character":10,"end_line":396,"end_character":14},"updated":"2026-01-14 12:00:29.000000000","message":"days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":393,"context_line":"     - Yes"},{"line_number":394,"context_line":"     - 6 months"},{"line_number":395,"context_line":"     - auto-renewed by cert-manager, as long as sc-adminep-ca-certificate is valid"},{"line_number":396,"context_line":"     - 30 days"},{"line_number":397,"context_line":"     - SystemController to subcloud communication will fail. Subcloud will"},{"line_number":398,"context_line":"       become unmanageable from SystemController"},{"line_number":399,"context_line":"   * - **System trusted CA Certificates (ssl_ca)**"}],"source_content_type":"text/x-rst","patch_set":3,"id":"f553bec3_045c2402","line":396,"range":{"start_line":396,"start_character":10,"end_line":396,"end_character":14},"in_reply_to":"078d168f_83ba878c","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":26026,"name":"Greg Waines","email":"greg.waines@windriver.com","username":"gwaines"},"change_message_id":"3d2215a623a87eeeadc5def3a9d7f63be3910686","unresolved":true,"context_lines":[{"line_number":420,"context_line":"     - Yes"},{"line_number":421,"context_line":"     - 90 days (cert-manager)"},{"line_number":422,"context_line":"     - IPsec certificate is auto-renewed by cron job, as long as system-local-ca is valid"},{"line_number":423,"context_line":"     - 15 days (cert-manager)"},{"line_number":424,"context_line":"     - Network traffic over management network is interrupted"},{"line_number":425,"context_line":""},{"line_number":426,"context_line":"Where:"}],"source_content_type":"text/x-rst","patch_set":3,"id":"0e31be6f_dde17555","line":423,"range":{"start_line":423,"start_character":10,"end_line":423,"end_character":15},"updated":"2026-01-14 12:00:29.000000000","message":"days before expiry","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"},{"author":{"_account_id":36019,"name":"Ngairangbam Mili","display_name":"Mili","email":"ngairangbam.mili@windriver.com","username":"miling08"},"change_message_id":"4fea7158065b94631ec28b50e6aff14f8875386d","unresolved":false,"context_lines":[{"line_number":420,"context_line":"     - Yes"},{"line_number":421,"context_line":"     - 90 days (cert-manager)"},{"line_number":422,"context_line":"     - IPsec certificate is auto-renewed by cron job, as long as system-local-ca is valid"},{"line_number":423,"context_line":"     - 15 days (cert-manager)"},{"line_number":424,"context_line":"     - Network traffic over management network is interrupted"},{"line_number":425,"context_line":""},{"line_number":426,"context_line":"Where:"}],"source_content_type":"text/x-rst","patch_set":3,"id":"90066b34_5f9681ba","line":423,"range":{"start_line":423,"start_character":10,"end_line":423,"end_character":15},"in_reply_to":"0e31be6f_dde17555","updated":"2026-01-14 13:58:28.000000000","message":"Done","commit_id":"8abd8331d338d6011976eee6f267fa2ae10ccbc3"}]}
