
"Shielded" nodes have a virtual TPM attached which is used for generating the client certificate, instead of using a bootstrap kubeconfig. Determining which to use happens during node startup based on the instance metadata.
"Shielded" nodes have a virtual TPM attached which is used for generating the client certificate, instead of using a bootstrap kubeconfig. Determining which to use happens during node startup based on the instance metadata.