Add doc for kube etcd cert renew

Skip-Release-Notes

Change-Id: I9fdc4936530a04c095830f0784d7647dc035b9d7
diff --git a/doc/source/admin/monitoring.rst b/doc/source/admin/monitoring.rst
index d196e15..d72a1b5 100644
--- a/doc/source/admin/monitoring.rst
+++ b/doc/source/admin/monitoring.rst
@@ -461,3 +461,17 @@
   .. code-block:: console
 
     openstack server list --all-projects --long -n --ip $IP
+
+``EtcdMembersDown``
+  If any alarms are fired from Promethetus for ``etcd`` issues such as ``TargetDown``,
+  ``etcdMembersDown``, or ``etcdInsufficientMembers``), it could be due to expired
+  certificates.  You can update the certificates that ``kube-prometheus-stack`` uses for
+  talking with ``etcd`` with the following commands:
+
+  .. code-block:: console
+
+    kubectl -n monitoring delete secret/kube-prometheus-stack-etcd-client-cert
+    kubectl -n monitoring create secret generic kube-prometheus-stack-etcd-client-cert \
+        --from-file=/etc/kubernetes/pki/etcd/ca.crt \
+        --from-file=/etc/kubernetes/pki/etcd/healthcheck-client.crt \
+        --from-file=/etc/kubernetes/pki/etcd/healthcheck-client.key