Version 1.12. This version is no longer supported. For information about how to upgrade to version 1.13, seeUpgrading Anthos on bare metalin the 1.13 documentation. For more information about supported and unsupported versions, see theVersion historypage in the latest documentation.
This document describes periodic maintenance that is required for your
GKE Enterprise clusters on bare metal.
Rotate certificate authorities
The certificate authorities (CAs) in a cluster are valid for five years, so you
mustrotate your CAsat least once every five years.
Certificates for cluster components
Cluster components use certificates for authentication. These components
include kube-apiserver, kube-controller-manager, kube-scheduler, etcd and
kubelet. The certificates are valid for 1 year and are renewed during clusterupgrade.
To prevent the certificates from expiring, you must upgrade your cluster at
least once a year.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-09-04 UTC."],[[["\u003cp\u003eGKE Enterprise clusters on bare metal require periodic maintenance.\u003c/p\u003e\n"],["\u003cp\u003eCertificate authorities (CAs) within the cluster must be rotated at least once every five years due to their five-year validity period.\u003c/p\u003e\n"],["\u003cp\u003eCertificates for cluster components, such as kube-apiserver and etcd, are valid for one year and are renewed during cluster upgrades.\u003c/p\u003e\n"],["\u003cp\u003eCluster upgrades are required at least once a year to prevent the expiration of component certificates.\u003c/p\u003e\n"]]],[],null,["# Required periodic maintenance\n\n\u003cbr /\u003e\n\nThis document describes periodic maintenance that is required for your\nGKE Enterprise clusters on bare metal.\n\nRotate certificate authorities\n------------------------------\n\nThe certificate authorities (CAs) in a cluster are valid for five years, so you\nmust\n[rotate your CAs](/anthos/clusters/docs/bare-metal/1.12/how-to/ca-rotation)\nat least once every five years.\n\nCertificates for cluster components\n-----------------------------------\n\nCluster components use certificates for authentication. These components\ninclude kube-apiserver, kube-controller-manager, kube-scheduler, etcd and\nkubelet. The certificates are valid for 1 year and are renewed during cluster\n[upgrade](/anthos/clusters/docs/bare-metal/1.12/how-to/upgrade).\nTo prevent the certificates from expiring, you must upgrade your cluster at\nleast once a year."]]