Skip to content

Fix rancher kubectl failing when a custom CA is configured - #711

Merged
pmatseykanets merged 1 commit into
rancher:mainfrom
pmatseykanets:fix-kubectl-cacerts-pem
Oct 9, 2026
Merged

pmatseykanets merged 1 commit into
rancher:mainfrom
pmatseykanets:fix-kubectl-cacerts-pem

Conversation

@pmatseykanets

@pmatseykanets pmatseykanets commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Issue: rancher/rancher#55988

Problem

The kubectl command treated the CA certificates saved at login as a file path. The saved value is the PEM content itself, so every kubectl run after logging in with --cacert failed with "file name too long". A certificate pool that could not be built also returned no TLS config and no error.

Solution

The kubectl command now builds its TLS config from the saved PEM content. Loading CA certificates from a file goes through the same PEM handling, and an empty certificate pool now returns an error.

The kubectl command treated the CA certificates saved at login as a file
path. The saved value is the PEM content itself, so every kubectl run after
logging in with --cacert failed with "file name too long". A certificate
pool that could not be built also returned no TLS config and no error.

The kubectl command now builds its TLS config from the saved PEM content.
Loading CA certificates from a file goes through the same PEM handling, and
an empty certificate pool now returns an error.
@pmatseykanets
pmatseykanets merged commit 12249f1 into rancher:main Oct 9, 2026
1 check passed
@pmatseykanets
pmatseykanets deleted the fix-kubectl-cacerts-pem branch October 9, 2026 14:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add support for ext.Tokens to Rancher CLI

3 participants