Add Let's Encrypt DNS-01 clouddns ClusterIssuers
unkin.net public DNS is delegated to Google Cloud DNS, so publicly-trusted wildcard certs need an ACME issuer using cert-manager's clouddns DNS-01 solver. The existing vault-issuer (internal PKI) is unchanged. - Add ClusterIssuers letsencrypt (prod) and letsencrypt-staging, both using a dns01 clouddns solver with a GCP service-account key. - Sync that key from Vault KV into Secret cert-manager-clouddns via a VaultStaticSecret + VaultAuth (role cert_manager_clouddns) and a dedicated cert-manager-clouddns service account. - Wire the new files into the base kustomization. - Whitelist cert-manager.io ClusterIssuer in the platform AppProject. The clouddns project and the KV secret value are set out-of-band. Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
This commit is contained in:
@@ -84,6 +84,8 @@ spec:
|
||||
kind: Certificate
|
||||
- group: 'cert-manager.io'
|
||||
kind: Issuer
|
||||
- group: 'cert-manager.io'
|
||||
kind: ClusterIssuer
|
||||
- group: 'gateway.networking.k8s.io'
|
||||
kind: GatewayClass
|
||||
- group: 'networking.k8s.io'
|
||||
|
||||
Reference in New Issue
Block a user