ERROR: x509: certificate is valid for 127.0.0.1, not 10.236.XX.121

Hello All.

I created a CRDB cluster in k8s and all works fine except I can’t access it from out of the k8s cluster.

kubectl describe csr tcc.node.cockroachdb-0
Name: tcc.node.cockroachdb-0
Labels:
Annotations:
CreationTimestamp: Fri, 10 Jul 2020 12:12:46 +0000
Requesting User: system:serviceaccount:tcc:cockroachdb
Status: Approved,Issued
Subject:
Common Name: node
Serial Number:
Organization: Cockroach
Subject Alternative Names:
DNS Names: localhost
cockroachdb-0.cockroachdb.tcc.svc.cluster.local
cockroachdb-0.cockroachdb
cockroachdb-public
cockroachdb-public.tcc.svc.cluster.local
IP Addresses: 127.0.0.1

kubectl get svc -n tcc
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
cockroachdb ClusterIP None 26257/TCP,8080/TCP 71m
cockroachdb-public LoadBalancer 10.245.XX.91 10.236.XX.121 26257:31164/TCP,8080:30844/TCP 71m

Is there a way to add service ip or DNS of cockroachdb-publi to CSR ?