Recovering from expired control plane certificates
However, you must manually approve the pending certificate signing requests (CSRs) to recover kubelet certificates. For user-provisioned installations, you might also need to approve pending kubelet serving CSRs.
Use the following steps to approve the pending CSRs:
For user-provisioned installations, approve each valid kubelet serving CSR: