avisession.go:666] Client error for URI: login. Error: Post "https://<AVI Controller>/login": tls: failed to verify certificate: x509: certificate signed by unknown authority 2.5.4
During AVI CA rotation, the new CA was patched into the cluster secrets, but AKO continued using a stale or incomplete trust bundle due to secret name/namespace mismatch
kubectl get secret -n tkg-system tkg-pkg-system-values -o jsonpath='{.data.tkgpackagevalues\.yaml}' | base64 -d > tkgpackagevalues.yamlcat tkgpackagevalues.yaml | base64 -w 0kubectl edit secret -n tkg-system tkg-pkg-tkg-system-addon