Courseiva

How to Renew the API Server Certificate Using kubeadm certs renew

An admin wants to check the expiration date of all certificates used by kubeadm components. Which command should be used?

⚠ Common exam trap

Candidates often confuse `kubeadm certs check-expiration` with `kubeadm upgrade plan` or `kubectl get certificates`, mistakenly thinking that upgrade planning or a generic kubectl command can reveal certificate expiry, when in fact only the kubeadm-specific subcommand provides this information.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubeadm certs check-expiration

The `kubeadm certs check-expiration` command is the correct tool to inspect the expiration dates of all certificates generated by kubeadm for cluster components, such as the API server, controller-manager, scheduler, and etcd. It reads the certificate files from the default kubeadm certificate directory (`/etc/kubernetes/pki`) and displays their remaining validity period in a human-readable table. This command is part of the kubeadm certificate management suite and is specifically designed for this purpose.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kubeadm certs check-expiration

    Why this is correct

    The kubeadm certs check-expiration command is specifically designed to scan the /etc/kubernetes/pki directory and the kubeconfig files in /etc/kubernetes to determine the validity and expiration dates of all control plane certificates. It displays a clear, tabular summary showing the residual lifetime, expiration date, and authority of each certificate. This is the standard, built-in tool for administrators to proactively manage cluster certificate lifecycles.

  • ✗

    kubeadm upgrade plan

    Why it's wrong here

    While kubeadm upgrade plan does perform a check on the current cluster state, its primary purpose is to analyze whether the cluster can be upgraded to a newer Kubernetes version. It checks the local kubeadm configuration, the versions of control plane components, and lists the available upgrade targets. It does not provide a comprehensive breakdown of certificate expiration dates for the active control plane components.

  • ✗

    kubeadm certs renew

    Why it's wrong here

    The kubeadm certs renew command is used to actively regenerate and extend the validity of Kubernetes control plane certificates, either individually or all at once. While it modifies the certificates to prevent expiration, it is an action-oriented command rather than an informational query tool. Running this without assessing the current expiration status first is not a safe or standard way to inspect certificate health.

  • ✗

    kubectl get certificates

    Why it's wrong here

    Out of the box, Kubernetes does not have a native core resource type named certificates that can be queried via kubectl get. While third-party tools like cert-manager introduce a Certificate Custom Resource Definition (CRD), standard Kubernetes control plane certificates managed by kubeadm are stored directly as files on the host filesystem and are not exposed as native Kubernetes API resources.

About these practice questions

This CKA question is part of Courseiva's 726-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.