added cert manager
This commit is contained in:
8
manifests/certmanager/issuer-secret.yaml
Normal file
8
manifests/certmanager/issuer-secret.yaml
Normal file
@ -0,0 +1,8 @@
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: cloudflare-api-token-secret
|
||||
namespace: cert-manager
|
||||
type: Opaque
|
||||
stringData:
|
||||
api-token: <API TOKEN>
|
16
manifests/certmanager/issuer.yaml
Normal file
16
manifests/certmanager/issuer.yaml
Normal file
@ -0,0 +1,16 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: cloudflare-clusterissuer
|
||||
spec:
|
||||
acme:
|
||||
email: kevin@nixit.it
|
||||
server: https://acme-v02.api.letsencrypt.org/directory
|
||||
privateKeySecretRef:
|
||||
name: cloudflare-clusterissuer-key
|
||||
solvers:
|
||||
- dns01:
|
||||
cloudflare:
|
||||
apiTokenSecretRef:
|
||||
name: cloudflare-api-token-secret
|
||||
key: api-token
|
5
manifests/certmanager/values.yaml
Normal file
5
manifests/certmanager/values.yaml
Normal file
@ -0,0 +1,5 @@
|
||||
crds:
|
||||
enabled: true
|
||||
extraArgs:
|
||||
- --dns01-recursive-nameservers-only
|
||||
- --dns01-recursive-nameservers=1.1.1.1:53,1.0.0.1:53
|
13
manifests/longhorn/certificate.yaml
Normal file
13
manifests/longhorn/certificate.yaml
Normal file
@ -0,0 +1,13 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: longhorn-ssl-certificate
|
||||
namespace: longhorn-system
|
||||
spec:
|
||||
# Secret names are always required.
|
||||
secretName: longhorn-ssl-certificate
|
||||
issuerRef:
|
||||
name: cloudflare-clusterissuer
|
||||
kind: ClusterIssuer
|
||||
dnsNames:
|
||||
- longhorn.nixit.it
|
@ -6,6 +6,10 @@ metadata:
|
||||
annotations:
|
||||
traefik.ingress.kubernetes.io/router.entrypoints: websecure
|
||||
spec:
|
||||
tls:
|
||||
- hosts:
|
||||
- longhorn.nixit.it
|
||||
secretName: longhorn-ssl-certificate
|
||||
rules:
|
||||
- host: longhorn.nixit.it
|
||||
http:
|
Reference in New Issue
Block a user