Downstream cluster - update kubecontroller manager

Issue here is, when CSR gets approved by kube-api/controller of downstream cluster, it shows cert is approved but not issued. it appears that kubecontroller manager should be running with below two args. Can you please let us know how to update the downsteam cluster kubectontroller?

  • extra_args:
  •  cluster-signing-cert-file: /etc/kubernetes/ssl/kube-ca.pem
  •  cluster-signing-key-file: /etc/kubernetes/ssl/kube-ca-key.pem

note: updating cluster.yaml is working for only upstream cluster only. we already have upstream and downstream clusters already built.