Where Does Teleport Store Certificates?
The tsh client keeps cluster certificates and keys in ~/.tsh, organized per proxy and user.
Last updated
Teleport stores client credentials in .tsh inside your home directory. Each proxy gets a folder with user certificates, keys, and known cluster state. Logging in writes them, and logout removes the session files.
Server identities live on the cluster side, never here. The kubeconfig tsh generates points at these certificates for Kubernetes access. Copying .tsh between machines works briefly, then short lived certs expire as designed.
Where Teleport stores this, by platform
~/.tsh
Keys and certs per proxy under keys and known_hosts style files. Manage with tsh login and tsh logout. Certs expire on their own schedule.
~/.tsh
Same client layout on Mac. The tsh kube command writes kube entries referencing these certs. Renew with tsh login when kubectl fails.
C:\Users\[username]\.tsh
Same tree under your profile. Short lived certs mean copies go stale fast. Prefer fresh logins over file surgery.
Frequently asked questions
How do I log out of every Teleport cluster?
Run tsh logout to clear session certs from .tsh. Stale entries stop working at expiry regardless. Delete the folder only with tsh closed.
Where is the Teleport kubeconfig?
Written into your kubeconfig by tsh kube login, pointing at the .tsh certificates. It breaks when certs expire. Re run the login to refresh both sides.
Notice an outdated path? Let us know.