ECK Update Certificate

We're trying to update our (externally sourced, CA signed) certificates for the Kibana and Elasticasearch public facing load balancer (using ECK in Azure). We've added the new certificate as a secret, but the loadbalancer/kibana-http service is still picking up the old certificate. Is there any documentation on updating certs without rebuilding the whole cluster?

