During a cluster upgrade, the kubelet on a worker node fails to start after updating the kubelet binary. The kubelet logs show: 'failed to load bootstrap client certificate: open /var/lib/kubelet/pki/kubelet-client-current.pem: no such file or directory'. What is the most likely cause?
Trap 1: The kubelet's node IP has changed
A changed node IP does not cause a missing-file error. It typically surfaces as TLS certificate validation failure because the kubelet's client certificate contains the old IP in its SANs, or the API server cannot reach the new IP. The bootstrap kubeconfig file would still exist and load correctly, so the failure would be at the authentication/TLS layer, not during file reading.
Trap 2: The kubelet's certificate has expired
An expired client certificate produces an x509 verification error such as 'certificate has expired or is not yet valid' when the kubelet tries to authenticate to the API server. This error occurs after the kubelet has already read the kubeconfig and loaded the certificate, whereas the reported failure is about the bootstrap kubeconfig file being absent. Certificate expiration would not prevent the file loader from finding the bootstrap kubeconfig.
Trap 3: The kubelet is using an outdated kubeconfig
An outdated kubeconfig points to an old API server address or old certificate authority, causing connection refused, unknown authority, or Unauthorized responses. The kubeconfig file itself is present, so the kubelet would not emit a 'missing file' error; instead it would fail during connection setup or credential validation. This is a configuration mismatch, not a file absence.
- A
The kubelet's node IP has changed
Why it fails: A changed node IP does not cause a missing-file error. It typically surfaces as TLS certificate validation failure because the kubelet's client certificate contains the old IP in its SANs, or the API server cannot reach the new IP. The bootstrap kubeconfig file would still exist and load correctly, so the failure would be at the authentication/TLS layer, not during file reading.
- B
The kubelet's certificate has expired
Why it fails: An expired client certificate produces an x509 verification error such as 'certificate has expired or is not yet valid' when the kubelet tries to authenticate to the API server. This error occurs after the kubelet has already read the kubeconfig and loaded the certificate, whereas the reported failure is about the bootstrap kubeconfig file being absent. Certificate expiration would not prevent the file loader from finding the bootstrap kubeconfig.
- C
The kubelet is using an outdated kubeconfig
Why it fails: An outdated kubeconfig points to an old API server address or old certificate authority, causing connection refused, unknown authority, or Unauthorized responses. The kubeconfig file itself is present, so the kubelet would not emit a 'missing file' error; instead it would fail during connection setup or credential validation. This is a configuration mismatch, not a file absence.
- D
The bootstrap kubeconfig file is missing or misconfigured
The bootstrap kubeconfig is the initial credential file the kubelet uses to create a CertificateSigningRequest and obtain a client certificate. If this file is missing or misconfigured (e.g., wrong server URL or incorrect CA data), the kubelet cannot even start the bootstrap flow and reports that it cannot load the bootstrap kubeconfig. During cluster upgrades, this file is often regenerated or expected to be at a specific path like /etc/kubernetes/bootstrap-kubelet.conf; if not present, the kubelet fails immediately.