Custom control-plane SAN¶
The vcluster API server certificate only lists localhost and in-cluster names by default. Reach the API under any other hostname, for example an ingress or a load balancer at vcluster.example.com, and TLS verification fails: the name is not in the certificate. controlPlane.proxy.extraSANs signs the cert for that extra name.
- add the external hostname to the proxy SAN list.
- apply it with Helm. The control-plane pod restarts and re-issues its certificate with the new SAN.
- confirm the hostname is in the served certificate.
- a client that reaches the API under
vcluster.example.comnow verifies the certificate instead of erroring withx509: certificate is valid for localhost, not vcluster.example.com.
This is the certificate half of a custom endpoint. The kubeconfig still points at localhost:8443 until you also set exportKubeConfig.server, covered in the next guide.
Manifests¶
https://www.vcluster.com/docs/vcluster/configure/vcluster-yaml/control-plane