A #kubernetes distribution issuing a system:masters cert with a 15 year expiry is definitely.... an interesting choice.

At least they do offer the possibility of revoking by rotating the CA key and requiring all new certs.