Some riffs on this idea:
A new
kubeadm ca-cert-hashcommand (name TBD) that just prints out the current CA hash. This would basically be the same thing as theopensslcommand we give in thekubeadm joindocs.Add a
--print-join-commandflag forkubeadm token createthat prints out the whole join command just likekubeadm initdoes. This would hopefully make it easy to automate around by running something likekubeadm token create --print-join-command >> worker_init.shduring provisioning.A new command
kubeadm token get <token id>that gets the full token given the ID, with a--print-join-commandflag to optionally print the full join command instead of just the token.