git clone https://github.com/yuyicai/update-kube-cert.git
cd update-kube-cert
chmod 755 update-kubeadm-cert.sh
./update-kubeadm-cert.sh all

# 查看证书有效期 
 openssl x509 -in /etc/kubernetes/pki/apiserver.crt -noout -text | grep Not
 
# 重装网络插件
kubectl delete ippool --all
kubectl delete felixconfiguration default
kubectl delete clusterrole calico-node
kubectl delete clusterrolebinding calico-node

kubectl apply -f https://docs.projectcalico.org/manifests/calico.yaml

重启服务器 或 重启kubelet