# Changing the number of members with the ScyllaDB Operator, expired certificate

**URL:** <https://forum.scylladb.com/t/changing-the-number-of-members-with-the-scylladb-operator-expired-certificate/1439>\
**Category:** ScyllaDB\
**Tags:** operator, kubernetes\
**Created:** [April 2, 2024, 4:54am UTC](https://forum.scylladb.com/t/changing-the-number-of-members-with-the-scylladb-operator-expired-certificate/1439 "2024-04-02T04:54:03Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Guy](https://sea2.discourse-cdn.com/flex016/user_avatar/forum.scylladb.com/guy/32/9_2.png) [@Guy](https://forum.scylladb.com/u/Guy)\
**Post date:** [April 2, 2024, 4:54am UTC](https://forum.scylladb.com/t/changing-the-number-of-members-with-the-scylladb-operator-expired-certificate/1439/1 "2024-04-02T04:54:03Z")

</div>

> [@](#):
>
> [**Originally from the User Slack**](https://scylladb-users.slack.com/)
> 
> ![Nino_Matos](https://us1.discourse-cdn.com/flex016/uploads/scylladb/original/1X/6f018fcaf757cbface1ed01ccbf6c61b91f421a8.jpeg) **@Nino_Matos:** updated:
> 
> Hi everybody,
> 
> I’m trying to scale my scylladb from 3 members to 4 members and i’m not being able to do it.
> 
> I’ve tried following the documentation: [https://github.com/scylladb/scylla-operator/blob/master/docs/source/generic.md#scale-a-scyllacluster](https://github.com/scylladb/scylla-operator/blob/master/docs/source/generic.md#scale-a-scyllacluster)  
> I’ve tried to scale the statefulset and the new node is not able to connect(maybe because there is no service). i’ve edited the members on the scylla cluster itself ([scylla.scylladb.com/v1/scyllaclusters](http://scylla.scylladb.com/v1/scyllaclusters)) using k9s and nothing…
> 
> My expectation was that when i change the members of the scylla cluster that would trigger a deployment of the new node.
> 
> i’ve tried running the kubectl way and got this:
> 
> ```auto
> kubectl -n scylla-cluster edit scyllaclusters.scylla.scylladb.com/scylla-non-prod
> error: scyllaclusters.scylla.scylladb.com "scylla-non-prod" could not be patched: Internal error occurred: failed calling webhook "webhook.scylla.scylladb.com": failed to call webhook: Post "<https://scylla-operator-webhook.scylla-operator.svc:443/validate?timeout=10s>": tls: failed to verify certificate: x509: certificate has expired or is not yet valid: current time 2024-01-25T09:18:34Z is after 2024-01-18T09:49:42Z
> You can run `kubectl replace -f /var/folders/y0/_3yf83qx6bvfz76fp6cp_pxc0000gn/T/kubectl-edit-2099248250.yaml` to try this update again.
> 
> ```
> 
> ![Maciej_Zimnoch](https://us1.discourse-cdn.com/flex016/uploads/scylladb/original/1X/9c48adc7bf80c75b465d5cc584019612d70a1ffe.jpeg) **@Maciej\_Zimnoch:** you shouldn’t modify resources managed by Operator on your own, instead modify ScyllaCluster resource.  
> Looks like webhook certificate is expired, new one should be automatically generated and picked up by the webhook. Please provide output of your:
> 
> ```auto
> kubectl -n scylla-operator get certificate scylla-operator-serving-cert -o yaml
> 
> ```
> 
> ![Aleksandar_Kocic](https://us1.discourse-cdn.com/flex016/uploads/scylladb/original/1X/c67ae04eeafb6c3e0bf0912dfae36a5af7fbe5b0.jpeg) **@Aleksandar\_Kocic:** Changing the number of members worked for me.
> 
> ![Nino_Matos](https://us1.discourse-cdn.com/flex016/uploads/scylladb/original/1X/6f018fcaf757cbface1ed01ccbf6c61b91f421a8.jpeg) **@Nino_Matos:** @Maciej\_Zimnoch yeah, that’s what i ended up doing. Changing the scyllacluster resource. The problem was that because my certificate was expired i couldn’t change the resource. Once i updated the certificate i was able to change the resource\<- @Aleksandar\_Kocic  
> Thanks for the suggestions 🙂
