Required periodic maintenance Stay organized with collections Save and categorize content based on your preferences.
This document describes periodic maintenance that is required for your Google Distributed Cloud clusters.
Rotate certificate authorities
The certificate authorities (CAs) in a cluster are valid for ten years, so you must rotate your CAs at least once every ten years.
Certificates for cluster components
Cluster components use certificates for authentication. These components include kube-apiserver, kube-controller-manager, kube-scheduler, etcd and kubelet. The certificates are valid for one year and are renewed during cluster upgrade. To prevent the certificates from expiring, you must upgrade your cluster at least once a year.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-10-24 UTC."],[],[]]