All four test runs from comment #4 appear to follow the same pattern as described in comment #5. The kubernetes-control-plane and kubeapi-load-balancer units update requested SANs on the relation, but vault reuses cached certificates and never issues new certificates with the updated SANs.
All four test runs from comment #4 appear to follow the same pattern as described in comment #5. The kubernetes- control- plane and kubeapi- load-balancer units update requested SANs on the relation, but vault reuses cached certificates and never issues new certificates with the updated SANs.