Kubelet Cert Expired Overnight: Check the Clock First

Symptom

Node flaps NotReady; x509: certificate has expired in kubelet logs.

Root cause

Clock drift makes valid certs look expired (or the cert genuinely aged out).

Fix, in order

1. Compare time skewtimedatectl && date # vs control plane time
2. Fix NTP, then verifytimedatectl set-ntp true
3. Genuinely expired: renew client certskubeadm certs renew # on the affected node

Prevent it coming back

Alert on clock skew > 100ms; NTP on every host, VMs especially.

Deep-dive article

Full walkthrough: Kubelet Cert Expired Overnight: Check the Clock First on the NinjaOps blog.

Run it on clean infra

Spinning up a fresh box to reproduce or escape this error?

Managed cloud hosting

Related

Cloud & DevOps tool comparisons · Hardware build guides

NinjaOps publishes free engineering guides. Some outbound links are affiliate links: they cost you nothing and support the site.

Last reviewed 2026-10-02 · NinjaOps SEO grid · DevOps blog