root@tools-sgebastion-11:~# openssl x509 -in /var/lib/puppet/ssl/certs/ca.pem -noout -dates notBefore=Jun 27 01:36:58 2017 GMT notAfter=Jun 27 01:36:58 2022 GMT
So far this doesn't seem to have caused any user facing impact, but I fear the k8s cluster might see some issues since we use puppet certs for etcd internal communication and apiserver->etcd traffic.