Downstream cluster - update kubecontroller manager

Team,
Issue here is, when CSR gets approved by kube-api/controller of downstream cluster, it shows cert is approved but not issued. it appears that kubecontroller manager should be running with below two args. Can you please let us know how to update the downsteam cluster kubectontroller?

  • extra_args:
  •  cluster-signing-cert-file: /etc/kubernetes/ssl/kube-ca.pem
    
  •  cluster-signing-key-file: /etc/kubernetes/ssl/kube-ca-key.pem
    

note: updating cluster.yaml is working for only upstream cluster only. we already have upstream and downstream clusters already built.