問題文
A cluster's component certificates are valid for one year. What operational practice does that lifetime require?
選択肢
- A shorter lifetime is always better, so the certificates should be reissued daily without exception.
- A tracked renewal process, because expiry stops components from authenticating to one another and the failure appears suddenly.
- Nothing, because the control plane renews all certificates automatically before they expire.
- A revocation list served to every component, so a certificate replaced before its expiry date can still be refused.