Files
website/content/ja/docs/setup/certificates.md
Takuya Tokuda edb233cac2 First Japanese l10n work for release-1.13 (#12998)
* [ja] add basic files for 1.13 (#11571)

* [ja] add basic files for 1.13

* [ja] add some base files

* Translate setup/independent/_index.md (#11573)

* Translate content/ja/docs/home/_index.md in Japanese (#11569)

* Translate content/ja/docs/setup/custom-cloud/_index.md in Japanese (#11572)

* Translate content/en/docs/setup/on-premises-vm/_index.md in Japanese (#11574)

* Translate content/ja/docs/setup/release/_index.md in Japanese (#11576)

* ja-trans: Translate content/ja/docs/tutorials/kubernetes-basics/explore/_index.md (#11580)

* Translate content/ja/docs/setup/turnkey/_index.md (#11582)

* Translate content/ja/docs/tutorials/kubernetes-basics/update/_index.m… (#11579)

* Translate content/ja/docs/tutorials/kubernetes-basics/update/_index.md in Japanese

* Fix title

* Translated Tutorials/Learn Kubenetes Basics/Deploy an App in Japanese. (#11583)

* translate tutorials/kubernetes-basics/expose/_index.md (#11584)

* Dev 1.13 ja.1 tutorials kubernetes basics scale (#11577)

* Translate content/ja/docs/tutorials/kubernetes-basics/scale/_index.md in Japanese

* Fix title

* translate deprecated state description (#11578)

*  Fix the build doesn't pass at dev-1.13-ja.1 (#11609)

* delete files not at minimum requirements to pass the build.

* copy necessary file for pass build from content/en

* translate content/ja/_index.html (#11585)

* ja-trans: add docs/_index.md (#11721)

* Remove copied docs/index.md by mistake. (#11735)

* Translate stable state description (#11642)

* translate stable state description

* Update content/ja/docs/templates/feature-state-stable.txt

Co-Authored-By: auifzysr <38824461+auifzysr@users.noreply.github.com>

* apply the suggestion directly

* Translate alpha state description (#11753)

* [ja] add ja section (#11581)

* [ja] translate case-studies (#12060)

* [ja] translate case-studies

* remove comment

* fix /ja/docs/ content (#12062)

* Translate content/ja/docs/tutorials/kubernetes-basics/create-cluster/_index.md in Japanese (#12059)

* [ja] translate supported doc versions (#12068)

* [ja] add ja.toml (#11595)

* Remove reviewers block from front matter. (#12092)

* Translate beta state description (#12023)

* [ja] translate setup (#12070)

* translate setup

* add translation

* Update _index.md

* Update _index.md

* 表記ゆれ

* 表記ゆれ

* [ja] translate what-is-kubernetes (#12065)

* translate what-is-kubernetes

* add more translation

* finish basic translation

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: d-kuro <34958495+d-kuro@users.noreply.github.com>

* Update what-is-kubernetes.md

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* fix new lines

* fix review

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update what-is-kubernetes.md

* Update what-is-kubernetes.md

* rephrase プラクティス to 知見

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* italic

* オーケストレーション

* [ja] tutorials/index (#12071)

* translate tutorial index

* fix page link

* add ja to path for kubernetes-basic  because it's already in progress of translation

* Update _index.md

* review

* remove typo

* Update content/ja/docs/tutorials/_index.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/_index.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* [ja] translate cri installation (#12095)

* [ja] translate cri installation

* Update content/ja/docs/setup/cri.md

Co-Authored-By: auifzysr <38824461+auifzysr@users.noreply.github.com>

* apply comments

* apply comments

* [ja]translate tutorials/kubernetes-basics (#12074)

* start translation

* translate index

* wording

* wording

* cluster-interactive

* cluster-intro

* update interactive

* update some data

* fix link

* deploy-intro

* japanize

* fix path for public data

* wording

* start translation of expose

* expose intro

* けーしょん

* scale-intro

* update-intro

* fix wrong word

* fix wording

* translate missing string

* Update content/ja/docs/tutorials/kubernetes-basics/_index.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/_index.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/scale/scale-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/expose/expose-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/expose/expose-interactive.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/_index.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* fix wording

* Update content/ja/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/create-cluster/cluster-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/scale/scale-interactive.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/expose/expose-interactive.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/explore/explore-interactive.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/deploy-app/deploy-interactive.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/create-cluster/cluster-interactive.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/deploy-app/deploy-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/explore/explore-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* Update content/ja/docs/tutorials/kubernetes-basics/scale/scale-intro.html

Co-Authored-By: inductor <kohei.ota@zozo.com>

* lowercase for kubectl

* ja-trans: tutorials/hello-minikube.md (#11648)

* trns-ja: tutorials/hello-minikube.md

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update hello-minikube.md

大変、大変遅くなりました。丁寧に見ていただいて感謝です。いただいたコメントを反映しました。

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update hello-minikube.md

<修正点>
・10行目の「本チュートリアルでは」を削除
・クラスターをクラスタに統一

* Update hello-minikube.md

10行目の実践を手を動かすに修正

* Update hello-minikube.md

10行目を「手を動かす準備はできていますか?本チュートリアルでは、Node.jsを使った簡単な"Hello World"を実行するKubernetesクラスタをビルドします。」に差し替え。

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* Update content/ja/docs/tutorials/hello-minikube.md

Co-Authored-By: lkougi <45655192+lkougi@users.noreply.github.com>

* ja-trans: setup/custom-cloud/coreos/ (#12731)

* ja-trans: setup/release/building-from-source/ (#12721)

* translate building-from-source

* improve translation

* ja-trans: translate setup/certificates/ (#12722)

* translate certificates.md

* change translation about Paths

* ja-trans: setup/custom-cloud/kubespray/ (#12733)

* ja-trans: setup/node-conformance/ (#12728)

* ja-trans: setup/node-conformance/

* Update content/ja/docs/setup/node-conformance.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* Update content/ja/docs/setup/node-conformance.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* Update content/ja/docs/setup/node-conformance.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* ja-trans: setup/cluster-large/ (#12723)

* ja-trans: setup/cluster-large/

* translate quota and addon

* ja-trans: setup/pick-right-solution/ (#12729)

* ja-trans: setup/pick-right-solution/

* revise translating solutions

* ending with a noun

* ja-trans: setup/custom-cloud/kops/ (#12732)

* ja-trans: setup/custom-cloud/kops/

* improve translation

* translate build

* translate explore and add-ons

* ja-trans: setup/independent/control-plane-flags/ (#12745)

* ja-trans: setup/minikube/ (#12724)

* ja-trans: setup/minikube/

* Update content/ja/docs/setup/minikube.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* translate features and add-ons

* improve translation

* improve translation

* fix translation style

* ja-trans: setup/multiple-zones/ (#12725)

* ja-trans: setup/multiple-zones/

* ja-trans: setup/multiple-zones/ (2)

* ending with a noun

* fix translation style

* ja-trans: setup/scratch/ (#12730)

* ja-trans: setup/scratch/

* revise translating connectivity

* improve translation

* Update content/ja/docs/setup/scratch.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* Update content/ja/docs/setup/scratch.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* Update content/ja/docs/setup/scratch.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* Update content/ja/docs/setup/scratch.md

LGTM

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* revise translation

* revert some words to English

* fix translation style

* fix title

* ja-trans: setup/independent/create-cluster-kubeadm/ (#12750)

* ja-trans: setup/independent/create-cluster-kubeadm/

* translate Instructions

* fix translation style

* ja-trans: setup/independent/kubelet-integration/ (#12754)

* ja-trans: setup/independent/kubelet-integration/

* fix translation style

* ja-trans: setup/independent/setup-ha-etcd-with-kubeadm/ (#12755)

* ja-trans: setup/independent/setup-ha-etcd-with-kubeadm/

* fix translation style

* ja-trans: setup/independent/troubleshooting-kubeadm/ (#12757)

* ja-trans: setup/independent/troubleshooting-kubeadm/

* pod -> Pod

* ja-trans: setup/on-premises-vm/cloudstack/ (#12772)

* ja-trans: setup/independent/high-availability/ (#12753)

* ja-trans: setup/independent/high-availability/

* fix translation style

* translate Stacked and worker node

* ja-trans: setup/on-premises-metal/krib/ (#12770)

* ja-trans: setup/on-premises-metal/krib/

* Update content/ja/docs/setup/on-premises-metal/krib.md

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* ja-trans: setup/on-premises-vm/ovirt/ (#12781)

* ja-trans: setup/on-premises-vm/dcos/ (#12780)

* ja-trans: setup/on-premises-vm/dcos/

* fix translation

* Update content/ja/docs/setup/on-premises-vm/dcos.md

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* ja-trans: setup/turnkey/alibaba-cloud/ (#12786)

* ja-trans: setup/turnkey/alibaba-cloud/

* tiny fix

* Update content/ja/docs/setup/turnkey/alibaba-cloud.md

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* fix translation

* ja-trans: setup/turnkey/aws/ (#12788)

* ja-trans: setup/turnkey/aws/

* translate production grade

* fix translation

* ja-trans: setup/release/notes/ (#12791)

* ja-trans: setup/independent/install-kubeadm.md (#12812)

* ja-trans: setup/independent/install-kubeadm.md

* ja-trans: fix internal links in setup/independent/install-kubeadm.md

* ja-trans: setup/turnkey/clc/ (#12824)

* ja-trans: setup/turnkey/clc/

* Update content/ja/docs/setup/turnkey/clc.md

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* Update content/ja/docs/setup/turnkey/clc.md

Co-Authored-By: makocchi-git <makocchi@gmail.com>

* ja-trans: setup/turnkey/stackpoint/ (#12853)

* ja-trans: concepts/ (#12820)

* ja-trans: concepts/

* fix translation

* ja: fix formatting in what is kubernetes (#12694)

* fix formatting in what is kubernetes

* Update content/ja/docs/concepts/overview/what-is-kubernetes.md

Co-Authored-By: inductor <kohei.ota@zozo.com>

* ?

* format (#12866)

* ja-trans: setup/turnkey/gce.md (#12813)

* ja-trans: setup/turnkey/gce.md

* Update content/ja/docs/setup/turnkey/gce.md

Co-Authored-By: auifzysr <38824461+auifzysr@users.noreply.github.com>

* Update content/ja/docs/setup/turnkey/gce.md

Co-Authored-By: auifzysr <38824461+auifzysr@users.noreply.github.com>

* ja-trans: modify a word in setup/turnkey/gce.md

* Translated docs/setup/turnkey/azure.md. (#12951)

* Translated docs/setup/turnkey/azure.md.

* Update content/ja/docs/setup/turnkey/azure.md

Applied a suggestion.

Co-Authored-By: dzeyelid <dzeyelid@gmail.com>

* Update content/ja/docs/setup/turnkey/azure.md

Applied a suggestion.

Co-Authored-By: dzeyelid <dzeyelid@gmail.com>

* Update content/ja/docs/setup/turnkey/azure.md

Applied suggestion.

Co-Authored-By: dzeyelid <dzeyelid@gmail.com>

* Applied review suggestions.

* Applied review suggestions.

* fix language setting order.
2019-03-07 10:17:41 -08:00

138 lines
9.9 KiB
Markdown

---
title: PKI証明書とその要件
content_template: templates/concept
---
{{% capture overview %}}
Kubernetes requires PKI certificates for authentication over TLS.
If you install Kubernetes with [kubeadm](/docs/reference/setup-tools/kubeadm/kubeadm/), the certificates that your cluster requires are automatically generated.
You can also generate your own certificates -- for example, to keep your private keys more secure by not storing them on the API server.
This page explains the certificates that your cluster requires.
{{% /capture %}}
{{% capture body %}}
## あなたのクラスタではどのように証明書が使われているのか
Kubernetes requires PKI for the following operations:
* Client certificates for the kubelet to authenticate to the API server
* Server certificate for the API server endpoint
* Client certificates for administrators of the cluster to authenticate to the API server
* Client certificates for the API server to talk to the kubelets
* Client certificate for the API server to talk to etcd
* Client certificate/kubeconfig for the controller manager to talk to the API server
* Client certificate/kubeconfig for the scheduler to talk to the API server.
* Client and server certificates for the [front-proxy][proxy]
{{< note >}}
`front-proxy` certificates are required only if you run kube-proxy to support [an extension API server](/docs/tasks/access-kubernetes-api/setup-extension-api-server/).
{{< /note >}}
etcd also implements mutual TLS to authenticate clients and peers.
## 証明書の保存場所
If you install Kubernetes with kubeadm, certificates are stored in `/etc/kubernetes/pki`. All paths in this documentation are relative to that directory.
## 手動で証明書を設定する
If you don't want kubeadm to generate the required certificates, you can create them in either of the following ways.
### 単一ルート認証局
You can create a single root CA, controlled by an administrator. This root CA can then create multiple intermediate CAs, and delegate all further creation to Kubernetes itself.
Required CAs:
| path | Default CN | description |
|------------------------|---------------------------|----------------------------------|
| ca.crt,key | kubernetes-ca | Kubernetes general CA |
| etcd/ca.crt,key | etcd-ca | For all etcd-related functions |
| front-proxy-ca.crt,key | kubernetes-front-proxy-ca | For the [front-end proxy][proxy] |
### 全ての証明書
If you don't wish to copy these private keys to your API servers, you can generate all certificates yourself.
Required certificates:
| Default CN | Parent CA | O (in Subject) | kind | hosts (SAN) |
|-------------------------------|---------------------------|----------------|----------------------------------------|---------------------------------------------|
| kube-etcd | etcd-ca | | server, client [<sup>1</sup>][etcdbug] | `localhost`, `127.0.0.1` |
| kube-etcd-peer | etcd-ca | | server, client | `<hostname>`, `<Host_IP>`, `localhost`, `127.0.0.1` |
| kube-etcd-healthcheck-client | etcd-ca | | client | |
| kube-apiserver-etcd-client | etcd-ca | system:masters | client | |
| kube-apiserver | kubernetes-ca | | server | `<hostname>`, `<Host_IP>`, `<advertise_IP>`, `[1]` |
| kube-apiserver-kubelet-client | kubernetes-ca | system:masters | client | |
| front-proxy-client | kubernetes-front-proxy-ca | | client | |
[1]: `kubernetes`, `kubernetes.default`, `kubernetes.default.svc`, `kubernetes.default.svc.cluster`, `kubernetes.default.svc.cluster.local`
where `kind` maps to one or more of the [x509 key usage][usage] types:
| kind | Key usage |
|--------|---------------------------------------------------------------------------------|
| server | digital signature, key encipherment, server auth |
| client | digital signature, key encipherment, client auth |
### 証明書のパス
Certificates should be placed in a recommended path (as used by [kubeadm][kubeadm]). Paths should be specified using the given argument regardless of location.
| Default CN | recommend key path | recommended cert path | command | key argument | cert argument |
|------------------------------|------------------------------|-----------------------------|----------------|------------------------------|-------------------------------------------|
| etcd-ca | | etcd/ca.crt | kube-apiserver | | --etcd-cafile |
| etcd-client | apiserver-etcd-client.crt | apiserver-etcd-client.crt | kube-apiserver | --etcd-certfile | --etcd-keyfile |
| kubernetes-ca | | ca.crt | kube-apiserver | --client-ca-file | |
| kube-apiserver | apiserver.crt | apiserver.key | kube-apiserver | --tls-cert-file | --tls-private-key |
| apiserver-kubelet-client | apiserver-kubelet-client.crt | | kube-apiserver | --kubelet-client-certificate | |
| front-proxy-client | front-proxy-client.key | front-proxy-client.crt | kube-apiserver | --proxy-client-cert-file | --proxy-client-key-file |
| | | | | | |
| etcd-ca | | etcd/ca.crt | etcd | | --trusted-ca-file, --peer-trusted-ca-file |
| kube-etcd | | etcd/server.crt | etcd | | --cert-file |
| kube-etcd-peer | etcd/peer.key | etcd/peer.crt | etcd | --peer-key-file | --peer-cert-file |
| etcd-ca | | etcd/ca.crt | etcdctl[2] | | --cacert |
| kube-etcd-healthcheck-client | etcd/healthcheck-client.key | etcd/healthcheck-client.crt | etcdctl[2] | --key | --cert |
[2]: For a liveness probe, if self-hosted
## ユーザアカウント用に証明書を設定する
You must manually configure these administrator account and service accounts:
| filename | credential name | Default CN | O (in Subject) |
|-------------------------|----------------------------|--------------------------------|----------------|
| admin.conf | default-admin | kubernetes-admin | system:masters |
| kubelet.conf | default-auth | system:node:`<nodename>` | system:nodes |
| controller-manager.conf | default-controller-manager | system:kube-controller-manager | |
| scheduler.conf | default-manager | system:kube-scheduler | |
1. For each config, generate an x509 cert/key pair with the given CN and O.
1. Run `kubectl` as follows for each config:
```shell
KUBECONFIG=<filename> kubectl config set-cluster default-cluster --server=https://<host ip>:6443 --certificate-authority <path-to-kubernetes-ca> --embed-certs
KUBECONFIG=<filename> kubectl config set-credentials <credential-name> --client-key <path-to-key>.pem --client-certificate <path-to-cert>.pem --embed-certs
KUBECONFIG=<filename> kubectl config set-context default-system --cluster default-cluster --user <credential-name>
KUBECONFIG=<filename> kubectl config use-context default-system
```
These files are used as follows:
| filename | command | comment |
|-------------------------|-------------------------|-----------------------------------------------------------------------|
| admin.conf | kubectl | Configures administrator user for the cluster |
| kubelet.conf | kubelet | One required for each node in the cluster. |
| controller-manager.conf | kube-controller-manager | Must be added to manifest in `manifests/kube-controller-manager.yaml` |
| scheduler.conf | kube-scheduler | Must be added to manifest in `manifests/kube-scheduler.yaml` |
[usage]: https://godoc.org/k8s.io/api/certificates/v1beta1#KeyUsage
[kubeadm]: /docs/reference/setup-tools/kubeadm/kubeadm/
[proxy]: /docs/tasks/access-kubernetes-api/configure-aggregation-layer/
{{% /capture %}}