fix: CertManager | create selfsigned CA cert to import into browsers
This commit is contained in:
@@ -1,19 +1,33 @@
|
|||||||
---
|
---
|
||||||
apiVersion: onepassword.com/v1
|
|
||||||
kind: OnePasswordItem
|
|
||||||
metadata:
|
|
||||||
name: ca-cert
|
|
||||||
namespace: cert-manager
|
|
||||||
annotations:
|
|
||||||
operator.1password.io/auto-restart: "true"
|
|
||||||
spec:
|
|
||||||
itemPath: "vaults/Lab/items/ca"
|
|
||||||
---
|
|
||||||
apiVersion: cert-manager.io/v1
|
apiVersion: cert-manager.io/v1
|
||||||
kind: ClusterIssuer
|
kind: ClusterIssuer
|
||||||
metadata:
|
metadata:
|
||||||
name: selfsigned-issuer
|
name: ca-issuer
|
||||||
namespace: cert-manager
|
namespace: cert-manager
|
||||||
|
spec:
|
||||||
|
selfSigned: {}
|
||||||
|
---
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: Certificate
|
||||||
|
metadata:
|
||||||
|
name: selfsigned-ca
|
||||||
|
namespace: cert-manager
|
||||||
|
spec:
|
||||||
|
isCA: true
|
||||||
|
commonName: "Shahab Dogar"
|
||||||
|
secretName: root-secret
|
||||||
|
privateKey:
|
||||||
|
algorithm: ECDSA
|
||||||
|
size: 256
|
||||||
|
issuerRef:
|
||||||
|
name: ca-issuer
|
||||||
|
kind: ClusterIssuer
|
||||||
|
group: cert-manager.io
|
||||||
|
---
|
||||||
|
apiVersion: cert-manager.io/v1
|
||||||
|
kind: ClusterIssuer
|
||||||
|
metadata:
|
||||||
|
name: cluster-issuer
|
||||||
spec:
|
spec:
|
||||||
ca:
|
ca:
|
||||||
secretName: ca-cert
|
secretName: root-secret
|
||||||
|
|||||||
@@ -11,7 +11,7 @@ ingress:
|
|||||||
enabled: true
|
enabled: true
|
||||||
className: nginx-internal
|
className: nginx-internal
|
||||||
annotations:
|
annotations:
|
||||||
cert-manager.io/cluster-issuer: selfsigned-issuer
|
cert-manager.io/cluster-issuer: cluster-issuer
|
||||||
hosts:
|
hosts:
|
||||||
- host: gitea.home
|
- host: gitea.home
|
||||||
paths:
|
paths:
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ persistentVolumeClaim:
|
|||||||
ingress:
|
ingress:
|
||||||
enabled: true
|
enabled: true
|
||||||
annotations:
|
annotations:
|
||||||
cert-manager.io/cluster-issuer: selfsigned-issuer
|
cert-manager.io/cluster-issuer: cluster-issuer
|
||||||
hosts:
|
hosts:
|
||||||
- pihole.home
|
- pihole.home
|
||||||
tls:
|
tls:
|
||||||
|
|||||||
@@ -4,7 +4,7 @@ grafana:
|
|||||||
enabled: true
|
enabled: true
|
||||||
ingressClassName: nginx-internal
|
ingressClassName: nginx-internal
|
||||||
annotations:
|
annotations:
|
||||||
cert-manager.io/cluster-issuer: selfsigned-issuer
|
cert-manager.io/cluster-issuer: cluster-issuer
|
||||||
hosts:
|
hosts:
|
||||||
- grafana.home
|
- grafana.home
|
||||||
tls:
|
tls:
|
||||||
|
|||||||
Reference in New Issue
Block a user