docs/custom_ca.md
When deploying a kops based Kubernetes cluster, kops will generate a Certificate Authority keypair for signing
various certificates. In some cases, you may want to provide your own CA keypair.
The following procedure will allow you to override the CA when creating a cluster. For the sake of this example, you have two files
ca.crt and ca.key.
cluster-name.comshould be the cluster name you put in thecluster.yaml
kops create -f cluster.yaml
kops create keypair kubernetes-ca --primary --cert ca.crt --key ca.key --name cluster-name.com
kops update cluster --yes
kubernetes-ca and provide our own values.kops update cluster --yes, which will generate all the certificates needed, referencing the keypair called kubernetes-ca we just defined (instead of generating its own).