apiVersion: v1 clusters: - cluster: # Not defining custom `certificate-authority`. # Without it, the localhost cert should be rejected. server: https://localhost:6443 insecure-skip-tls-verify: false # Same as external-without-ca.kubeconfig but with explicit false here. name: local contexts: - context: cluster: local namespace: default user: user name: Default current-context: Default kind: Config preferences: {} users: - name: user user: client-certificate: external-cert.pem client-key: external-key.rsa