[root@k8s-master .kube]# kubeadm init phase certs all --apiserver-advertise-address=0.0.0.0 --apiserver-cert-extra-sans=10.96.0.1,172.17.0.14,xxx.xxx.xxx.xxx(公网ip)I062715:10:39.0691067777version.go:252]remoteversionismuchnewer:v1.21.2; fallingbackto:stable-1.18W062715:10:40.9823807777configset.go:202]WARNING:kubeadmcannotvalidatecomponentconfigsforAPIgroups [kubelet.config.k8s.io kubeproxy.config.k8s.io][certs] Using certificateDir folder "/etc/kubernetes/pki"[certs] Using existing ca certificate authority[certs] Generating "apiserver" certificate and key[certs] apiserver serving cert is signed for DNS names [k8s-master kubernetes kubernetes.default kubernetes.default.svc kubernetes.default.svc.cluster.local] and IPs [10.96.0.1172.17.0.1410.96.0.1172.17.0.14 106.55.152.92][certs] Using existing apiserver-kubelet-client certificate and key on disk[certs] Using existing front-proxy-ca certificate authority[certs] Using existing front-proxy-client certificate and key on disk[certs] Using existing etcd/ca certificate authority[certs] Using existing etcd/server certificate and key on disk[certs] Using existing etcd/peer certificate and key on disk[certs] Using existing etcd/healthcheck-client certificate and key on disk[certs] Using existing apiserver-etcd-client certificate and key on disk[certs] Using the existing "sa" key