diff --git a/flake.nix b/flake.nix
index 4346248..79869bd 100644
--- a/flake.nix
+++ b/flake.nix
@@ -761,16 +761,17 @@
                   preStart =
                     if (cfg.hosts.${name}.role == "master")
                     then
-                      ''
-                        mkdir -p /etc/kubernetes/pki
-                        cd /etc/kubernetes/pki
-                        if [ ! -f apiserver-etcd-client.crt ]
-                        then
-                          cat ${apiserver-etcd-client-csr-json} | ${pkgs.cfssl}/bin/cfssl gencert -ca=${cfg.etcd.certPath} -ca-key=${cfg.etcd.keyPath} -config=${ca-config-json} -profile=client - | ${pkgs.cfssl}/bin/cfssljson -bare apiserver-etcd-client
-                          mv apiserver-etcd-client.pem apiserver-etcd-client.crt
-                          mv apiserver-etcd-client-key.pem apiserver-etcd-client.key
-                        fi
-                      ''
+                      ""
+                    # ''
+                    #   mkdir -p /etc/kubernetes/pki
+                    #   cd /etc/kubernetes/pki
+                    #   if [ ! -f apiserver-etcd-client.crt ]
+                    #   then
+                    #     cat ${apiserver-etcd-client-csr-json} | ${pkgs.cfssl}/bin/cfssl gencert -ca=${cfg.etcd.certPath} -ca-key=${cfg.etcd.keyPath} -config=${ca-config-json} -profile=client - | ${pkgs.cfssl}/bin/cfssljson -bare apiserver-etcd-client
+                    #     mv apiserver-etcd-client.pem apiserver-etcd-client.crt
+                    #     mv apiserver-etcd-client-key.pem apiserver-etcd-client.key
+                    #   fi
+                    # ''
                     else
                       "";
                   serviceConfig = {