Skip to content

Commit

Permalink
Merge pull request #47647 from windsonsea/certsy
Browse files Browse the repository at this point in the history
[zh] Sync kubeadm_certs.md and its dependent files
  • Loading branch information
k8s-ci-robot authored Aug 24, 2024
2 parents b4a0808 + 96e8e0b commit a4d8c11
Show file tree
Hide file tree
Showing 18 changed files with 53 additions and 52 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ help for certs
<!--
### Options inherited from parent commands
-->
### 继承于父命令的选项
### 从父命令继承的选项

<table style="width: 100%; table-layout: fixed;">
<colgroup>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -117,11 +117,13 @@ text|json|yaml|go-template|go-template-file|template|templatefile|jsonpath|jsonp
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;">
<p>
<!--
<p>The kubeconfig file to use when talking to the cluster. If the flag is not set, a set of standard locations can be searched for an existing kubeconfig file.</p>
The kubeconfig file to use when talking to the cluster. If the flag is not set, a set of standard locations can be searched for an existing kubeconfig file.
-->
<p>在和集群连接时使用该 kubeconfig 文件。
如果此标志未被设置,那么将会在一些标准的位置去搜索存在的 kubeconfig 文件。</p>
在和集群连接时使用该 kubeconfig 文件。
如果此标志未被设置,那么将会在一些标准的位置去搜索存在的 kubeconfig 文件。
</p>
</td>
</tr>

Expand All @@ -145,7 +147,7 @@ If true, keep the managedFields when printing objects in JSON or YAML format.
<!--
### Options inherited from parent commands
-->
### 继承于父命令的选项
### 从父命令继承的选项

<table style="width: 100%; table-layout: fixed;">
<colgroup>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<!--
Generate keys and certificate signing requests
-->
生成密钥和证书签名请求
生成密钥和证书签名请求

<!--
### Synopsis
Expand All @@ -18,7 +18,7 @@ Generates keys and certificate signing requests (CSRs) for all the certificates
<!--
This command is designed for use in [Kubeadm External CA Mode](https://kubernetes.io/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#external-ca-mode). It generates CSRs which you can then submit to your external certificate authority for signing.
-->
此命令设计用于 [Kubeadm 外部 CA 模式](https://kubernetes.io/zh-cn/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#external-ca-mode)
此命令设计用于 [Kubeadm 外部 CA 模式](/zh-cn/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#external-ca-mode)
它生成你可以提交给外部证书颁发机构进行签名的 CSR。

<!--
Expand All @@ -43,7 +43,7 @@ kubeadm certs generate-csr [flags]
kubeadm certs generate-csr --kubeconfig-dir /tmp/etc-k8s --cert-dir /tmp/etc-k8s/pki
```
-->
```
```shell
# 以下命令将为所有控制平面证书和 kubeconfig 文件生成密钥和 CSR:
kubeadm certs generate-csr --kubeconfig-dir /tmp/etc-k8s --cert-dir /tmp/etc-k8s/pki
```
Expand Down Expand Up @@ -126,7 +126,7 @@ The path where to save the kubeconfig file.
<!--
### Options inherited from parent commands
-->
### 继承于父命令的选项
### 从父命令继承的选项

<table style="width: 100%; table-layout: fixed;">
<colgroup>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -91,11 +91,13 @@ kubeadm certs renew admin.conf [flags]
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;">
<p>
<!--
<p>The kubeconfig file to use when talking to the cluster. If the flag is not set, a set of standard locations can be searched for an existing kubeconfig file.</p>
The kubeconfig file to use when talking to the cluster. If the flag is not set, a set of standard locations can be searched for an existing kubeconfig file.
-->
<p>与集群通信时使用的 kubeconfig 文件。
如果未设置该参数,则可以在一组标准位置中搜索现有的 kubeconfig 文件。</p>
与集群通信时使用的 kubeconfig 文件。
如果未设置该参数,则可以在一组标准位置中搜索现有的 kubeconfig 文件。
</p>
</td>
</tr>

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -55,10 +55,10 @@ kubeadm certs renew apiserver [flags]
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;">
<p>
<!--
The path where to save the certificates.
-->
<p>
保存证书的路径。
</p>
</td>
Expand All @@ -69,10 +69,10 @@ The path where to save the certificates.
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;">
<p>
<!--
Path to a kubeadm configuration file.
-->
<p>
kubeadm 配置文件的路径。
</p>
</td>
Expand All @@ -83,10 +83,10 @@ kubeadm 配置文件的路径。
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;">
<p>
<!--
help for apiserver
-->
<p>
apiserver 子操作的帮助命令。
</p>
</td>
Expand All @@ -103,10 +103,10 @@ apiserver 子操作的帮助命令。

<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;">
<p>
<!--
The kubeconfig file to use when talking to the cluster. If the flag is not set, a set of standard locations can be searched for an existing kubeconfig file.
-->
<p>
与集群通信时使用的 kubeconfig 文件。
如果未设置该参数,则可以在一组标准位置中搜索现有的 kubeconfig 文件。
</p>
Expand All @@ -133,10 +133,10 @@ The kubeconfig file to use when talking to the cluster. If the flag is not set,
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;">
<p>
<!--
[EXPERIMENTAL] The path to the 'real' host root filesystem.
-->
<p>
[实验] 到 '真实' 主机根文件系统的路径。
</p>
</td>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -109,10 +109,12 @@ kubeadm certs renew controller-manager.conf [flags]
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;">
<p>
<!--
Use the Kubernetes certificate API to renew certificates
-->
使用 Kubernetes 证书 API 续订证书。
<p>
</td>
</tr>

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -55,10 +55,10 @@ kubeadm certs renew etcd-healthcheck-client [flags]
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;">
<p>
<!--
The path where to save the certificates.
-->
<p>
保存证书的路径。
</p>
</td>
Expand All @@ -69,10 +69,10 @@ The path where to save the certificates.
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;">
<p>
<!--
Path to a kubeadm configuration file.
-->
<p>
kubeadm 配置文件的路径。
</p>
</td>
Expand All @@ -82,10 +82,10 @@ kubeadm 配置文件的路径。
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;">
<p>
<!--
help for etcd-healthcheck-client
-->
<p>
etcd-healthcheck-client 操作的帮助命令。
</p>
</td>
Expand All @@ -101,10 +101,10 @@ etcd-healthcheck-client 操作的帮助命令。
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;">
<p>
<!--
The kubeconfig file to use when talking to the cluster. If the flag is not set, a set of standard locations can be searched for an existing kubeconfig file.
-->
<p>
与集群通信时使用的 kubeconfig 文件。
如果未设置该参数,则可以在一组标准位置中搜索现有的 kubeconfig 文件。
</p>
Expand All @@ -131,10 +131,10 @@ The kubeconfig file to use when talking to the cluster. If the flag is not set,
</tr>
<tr>
<td></td><td style="line-height: 130%; word-wrap: break-word;">
<p>
<!--
[EXPERIMENTAL] The path to the 'real' host root filesystem.
-->
<p>
[实验] 到 '真实' 主机根文件系统的路径。
</p>
</td>
Expand Down
55 changes: 25 additions & 30 deletions content/zh-cn/docs/reference/setup-tools/kubeadm/kubeadm-certs.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,8 @@ weight: 90
For more details on how these commands can be used, see
[Certificate Management with kubeadm](/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/).
-->
`kubeadm certs` 提供管理证书的工具。关于如何使用这些命令的细节,可参见
[使用 kubeadm 管理证书](/zh-cn/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/)
`kubeadm certs` 提供管理证书的工具。关于如何使用这些命令的细节,
可参见[使用 kubeadm 管理证书](/zh-cn/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/)

## kubeadm certs {#cmd-certs}

Expand All @@ -20,33 +20,31 @@ A collection of operations for operating Kubernetes certificates.
用来操作 Kubernetes 证书的一组命令。

{{< tabs name="tab-certs" >}}
{{< tab name="概览" include="generated/kubeadm_certs.md" />}}
{{< tab name="概览" include="generated/kubeadm_certs/_index.md" />}}
{{< /tabs >}}

## kubeadm certs renew {#cmd-certs-renew}

<!--
You can renew all Kubernetes certificates using the `all` subcommand or renew them selectively.
For more details see [Manual certificate renewal](/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#manual-certificate-renewal).
-->
你可以使用 `all` 子命令来续订所有 Kubernetes 证书,也可以选择性地续订部分证书。
更多的相关细节,可参见
[手动续订证书](/zh-cn/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#manual-certificate-renewal)
你可以使用 `all` 子命令来续订所有 Kubernetes 证书,也可以选择性地续订部分证书。更多的相关细节,
可参见[手动续订证书](/zh-cn/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#manual-certificate-renewal)

{{< tabs name="tab-certs-renew" >}}
{{< tab name="renew" include="generated/kubeadm_certs_renew.md" />}}
{{< tab name="all" include="generated/kubeadm_certs_renew_all.md" />}}
{{< tab name="admin.conf" include="generated/kubeadm_certs_renew_admin.conf.md" />}}
{{< tab name="apiserver-etcd-client" include="generated/kubeadm_certs_renew_apiserver-etcd-client.md" />}}
{{< tab name="apiserver-kubelet-client" include="generated/kubeadm_certs_renew_apiserver-kubelet-client.md" />}}
{{< tab name="apiserver" include="generated/kubeadm_certs_renew_apiserver.md" />}}
{{< tab name="controller-manager.conf" include="generated/kubeadm_certs_renew_controller-manager.conf.md" />}}
{{< tab name="etcd-healthcheck-client" include="generated/kubeadm_certs_renew_etcd-healthcheck-client.md" />}}
{{< tab name="etcd-peer" include="generated/kubeadm_certs_renew_etcd-peer.md" />}}
{{< tab name="etcd-server" include="generated/kubeadm_certs_renew_etcd-server.md" />}}
{{< tab name="front-proxy-client" include="generated/kubeadm_certs_renew_front-proxy-client.md" />}}
{{< tab name="scheduler.conf" include="generated/kubeadm_certs_renew_scheduler.conf.md" />}}
{{< tab name="super-admin.conf" include="generated/kubeadm_certs_renew_super-admin.conf.md" />}}
{{< tab name="renew" include="generated/kubeadm_certs/kubeadm_certs_renew.md" />}}
{{< tab name="all" include="generated/kubeadm_certs/kubeadm_certs_renew_all.md" />}}
{{< tab name="admin.conf" include="generated/kubeadm_certs/kubeadm_certs_renew_admin.conf.md" />}}
{{< tab name="apiserver-etcd-client" include="generated/kubeadm_certs/kubeadm_certs_renew_apiserver-etcd-client.md" />}}
{{< tab name="apiserver-kubelet-client" include="generated/kubeadm_certs/kubeadm_certs_renew_apiserver-kubelet-client.md" />}}
{{< tab name="apiserver" include="generated/kubeadm_certs/kubeadm_certs_renew_apiserver.md" />}}
{{< tab name="controller-manager.conf" include="generated/kubeadm_certs/kubeadm_certs_renew_controller-manager.conf.md" />}}
{{< tab name="etcd-healthcheck-client" include="generated/kubeadm_certs/kubeadm_certs_renew_etcd-healthcheck-client.md" />}}
{{< tab name="etcd-peer" include="generated/kubeadm_certs/kubeadm_certs_renew_etcd-peer.md" />}}
{{< tab name="etcd-server" include="generated/kubeadm_certs/kubeadm_certs_renew_etcd-server.md" />}}
{{< tab name="front-proxy-client" include="generated/kubeadm_certs/kubeadm_certs_renew_front-proxy-client.md" />}}
{{< tab name="scheduler.conf" include="generated/kubeadm_certs/kubeadm_certs_renew_scheduler.conf.md" />}}
{{< tab name="super-admin.conf" include="generated/kubeadm_certs/kubeadm_certs_renew_super-admin.conf.md" />}}
{{< /tabs >}}

## kubeadm certs certificate-key {#cmd-certs-certificate-key}
Expand All @@ -63,7 +61,7 @@ to enable the automatic copy of certificates when joining additional control-pla
命令,从而在添加新的控制面节点时能够自动完成证书复制。

{{< tabs name="tab-certs-certificate-key" >}}
{{< tab name="certificate-key" include="generated/kubeadm_certs_certificate-key.md" />}}
{{< tab name="certificate-key" include="generated/kubeadm_certs/kubeadm_certs_certificate-key.md" />}}
{{< /tabs >}}

## kubeadm certs check-expiration {#cmd-certs-check-expiration}
Expand All @@ -73,13 +71,11 @@ This command checks expiration for the certificates in the local PKI managed by
For more details see
[Check certificate expiration](/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#check-certificate-expiration).
-->
此命令检查 kubeadm 所管理的本地 PKI 中的证书是否以及何时过期。
更多的相关细节,可参见
[检查证书过期](/zh-cn/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#check-certificate-expiration)

此命令检查 kubeadm 所管理的本地 PKI 中的证书是否以及何时过期。更多的相关细节,
可参见[检查证书过期](/zh-cn/docs/tasks/administer-cluster/kubeadm/kubeadm-certs/#check-certificate-expiration)

{{< tabs name="tab-certs-check-expiration" >}}
{{< tab name="check-expiration" include="generated/kubeadm_certs_check-expiration.md" />}}
{{< tab name="check-expiration" include="generated/kubeadm_certs/kubeadm_certs_check-expiration.md" />}}
{{< /tabs >}}

## kubeadm certs generate-csr {#cmd-certs-generate-csr}
Expand All @@ -91,11 +87,11 @@ on how to use the command see
[Signing certificate signing requests (CSR) generated by kubeadm](/docs/tasks/administer-cluster/kubeadm/kubeadm-certs#signing-csr).
-->
此命令可用来为所有控制面证书和 kubeconfig 文件生成密钥和 CSR(签名请求)。
用户可以根据自身需要选择 CA 为 CSR 签名。要了解如何使用该命令的更多信息,请参阅
[签署由 kubeadm 生成的证书签名请求(CSR)](/zh-cn/docs/tasks/administer-cluster/kubeadm/kubeadm-certs#signing-csr)
用户可以根据自身需要选择 CA 为 CSR 签名。要了解如何使用该命令的更多信息,
请参阅[签署由 kubeadm 生成的证书签名请求(CSR)](/zh-cn/docs/tasks/administer-cluster/kubeadm/kubeadm-certs#signing-csr)

{{< tabs name="tab-certs-generate-csr" >}}
{{< tab name="generate-csr" include="generated/kubeadm_certs_generate-csr.md" />}}
{{< tab name="generate-csr" include="generated/kubeadm_certs/kubeadm_certs_generate-csr.md" />}}
{{< /tabs >}}

## {{% heading "whatsnext" %}}
Expand All @@ -114,4 +110,3 @@ on how to use the command see
* 用来回滚 `kubeadm init``kubeadm join` 对当前主机所做修改的
[kubeadm reset](/zh-cn/docs/reference/setup-tools/kubeadm/kubeadm-reset/)
命令

0 comments on commit a4d8c11

Please sign in to comment.