Follow these steps to update the SSL certificate of the ingress in a Rancher High Availability installation or switch from the default self-signed to a custom certificate:
- Create or update the
tls-rancher-ingress
k8s secret resource with the new certificate and private key - Create or update the
tls-ca
k8s secret resource with the root CA certificate (only required when using a private CA) - Update Rancher installation using Helm CLI
- Reconfigure Rancher Agents to trust the new CA certificate