Node flaps NotReady; x509: certificate has expired in kubelet logs.
Clock drift makes valid certs look expired (or the cert genuinely aged out).
timedatectl && date # vs control plane timetimedatectl set-ntp truekubeadm certs renew # on the affected nodeAlert on clock skew > 100ms; NTP on every host, VMs especially.
Full walkthrough: Kubelet Cert Expired Overnight: Check the Clock First on the NinjaOps blog.
Spinning up a fresh box to reproduce or escape this error?
Managed cloud hostingNinjaOps publishes free engineering guides. Some outbound links are affiliate links: they cost you nothing and support the site.
Last reviewed 2026-10-02 · NinjaOps SEO grid · DevOps blog