Open
Description
Component: salt
Why this is needed: To keep things neatly organized
What should be done:
Store all certs used by the salt-master
static Pod under /etc/salt/pki
:
- SaltAPI server certificate is already at
/etc/salt/pki/api/salt-api.crt
- Salt master's kubeconfig is at
/etc/salt/master-kubeconfig.conf
, should go under/etc/salt/pki/master/kubeconfig.conf
- Salt master's etcd client certificate is at
/etc/kubernetes/pki/etcd/salt-master-etcd-client.crt
, should go under/etc/salt/pki/master/etcd-client.crt