Add doc for kube etcd cert renew
Skip-Release-Notes
Change-Id: I9fdc4936530a04c095830f0784d7647dc035b9d7
diff --git a/doc/source/admin/monitoring.rst b/doc/source/admin/monitoring.rst
index d196e15..d72a1b5 100644
--- a/doc/source/admin/monitoring.rst
+++ b/doc/source/admin/monitoring.rst
@@ -461,3 +461,17 @@
.. code-block:: console
openstack server list --all-projects --long -n --ip $IP
+
+``EtcdMembersDown``
+ If any alarms are fired from Promethetus for ``etcd`` issues such as ``TargetDown``,
+ ``etcdMembersDown``, or ``etcdInsufficientMembers``), it could be due to expired
+ certificates. You can update the certificates that ``kube-prometheus-stack`` uses for
+ talking with ``etcd`` with the following commands:
+
+ .. code-block:: console
+
+ kubectl -n monitoring delete secret/kube-prometheus-stack-etcd-client-cert
+ kubectl -n monitoring create secret generic kube-prometheus-stack-etcd-client-cert \
+ --from-file=/etc/kubernetes/pki/etcd/ca.crt \
+ --from-file=/etc/kubernetes/pki/etcd/healthcheck-client.crt \
+ --from-file=/etc/kubernetes/pki/etcd/healthcheck-client.key