This knowledge base article outlines the process for rotating the NSX Advanced Load Balancer (AVI) certificate and updating it on the VMware supervisor. Restarting the AKO pod ensures it picks up the new certificate to communicate with AVI. Expired certificates can lead to critical issues, including:
22.1.7
Certificates expired
Create a new controller certificate
Assign this new controller certificate to the AVI controller itself
Validate
kubectl get pods -A | grep -i akokubectl delete pod vmware-system-ako-ako-controller-manager-#### -n vmware-system-ako