Currently if etcd.yaml does not have a diff on "kubeadm upgrade" certificate renewal for it is also skipped. Check if kube-apiserver.yaml needs an upgrade, if so and if cert renewal is not disabled, renew etcd's certs and restart its static pod.