Add Let's Encrypt RFC2136/TSIG ClusterIssuers #327

Merged
benvin merged 2 commits from benvin/letsencrypt-clouddns-issuer into main 2026-08-02 17:47:39 +10:00
Owner

Publicly-trusted wildcard certs via Let's Encrypt DNS-01, solved over RFC2136/TSIG against our own BIND. A one-time CNAME self-delegates _acme-challenge.unkin.net into the acme.unkin.net zone served by bind-external; cert-manager writes the challenge TXT there. No GCP/clouddns and no Vault secret involved. The existing vault-issuer (internal PKI) is untouched.

  • Add ClusterIssuers letsencrypt (prod) and letsencrypt-staging, both using a dns01 rfc2136 solver: nameserver 198.18.199.53:53, key certmanager, HMACSHA256, tsigSecretSecretRef -> reflected Secret certmanager-tsig key secret.
  • Whitelist cert-manager.io ClusterIssuer in the platform AppProject.

Depends on #329 (bind-external: the acme.unkin.net zone, the certmanager TSIG key reflected into cert-manager, and the 198.18.199.53 nameserver) and on the one-time Google Cloud DNS delegation + NAT of the public IP :53 to 198.18.199.53. Earlier clouddns/Vault commits on this branch are reverted.

Publicly-trusted wildcard certs via Let's Encrypt DNS-01, solved over RFC2136/TSIG against our own BIND. A one-time CNAME self-delegates `_acme-challenge.unkin.net` into the `acme.unkin.net` zone served by bind-external; cert-manager writes the challenge TXT there. No GCP/clouddns and no Vault secret involved. The existing `vault-issuer` (internal PKI) is untouched. - Add ClusterIssuers `letsencrypt` (prod) and `letsencrypt-staging`, both using a dns01 rfc2136 solver: nameserver `198.18.199.53:53`, key `certmanager`, HMACSHA256, `tsigSecretSecretRef` -> reflected Secret `certmanager-tsig` key `secret`. - Whitelist `cert-manager.io ClusterIssuer` in the platform AppProject. Depends on #329 (bind-external: the acme.unkin.net zone, the certmanager TSIG key reflected into cert-manager, and the 198.18.199.53 nameserver) and on the one-time Google Cloud DNS delegation + NAT of the public IP :53 to 198.18.199.53. Earlier clouddns/Vault commits on this branch are reverted.
unkinben added 1 commit 2026-08-02 17:07:31 +10:00
Add Let's Encrypt DNS-01 clouddns ClusterIssuers
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
779e448686
unkin.net public DNS is delegated to Google Cloud DNS, so publicly-trusted
wildcard certs need an ACME issuer using cert-manager's clouddns DNS-01
solver. The existing vault-issuer (internal PKI) is unchanged.

- Add ClusterIssuers letsencrypt (prod) and letsencrypt-staging, both using
  a dns01 clouddns solver with a GCP service-account key.
- Sync that key from Vault KV into Secret cert-manager-clouddns via a
  VaultStaticSecret + VaultAuth (role cert_manager_clouddns) and a dedicated
  cert-manager-clouddns service account.
- Wire the new files into the base kustomization.
- Whitelist cert-manager.io ClusterIssuer in the platform AppProject.

The clouddns project and the KV secret value are set out-of-band.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
unkinben added 1 commit 2026-08-02 17:29:00 +10:00
Switch Let's Encrypt ClusterIssuers to RFC2136/TSIG solver
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
4434265cf6
The clouddns approach is dropped in favour of self-delegating the ACME
challenge to our own BIND: a one-time CNAME sends _acme-challenge.unkin.net
into acme.unkin.net (served by bind-external), and cert-manager solves DNS-01
via RFC2136+TSIG against it. No GCP service account or Vault KV secret needed.

- Replace the dns01 clouddns solver in both ClusterIssuers with rfc2136
  (nameserver 198.18.199.53:53, key certmanager, HMACSHA256, secret
  certmanager-tsig reflected into the cert-manager namespace).
- Remove the now-unneeded VaultAuth, VaultStaticSecret and clouddns
  ServiceAccount.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
unkinben changed title from Add Let's Encrypt DNS-01 clouddns ClusterIssuers to Add Let's Encrypt RFC2136/TSIG ClusterIssuers 2026-08-02 17:29:10 +10:00
benvin merged commit c0c75d1bbb into main 2026-08-02 17:47:39 +10:00
benvin deleted branch benvin/letsencrypt-clouddns-issuer 2026-08-02 17:47:40 +10:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/argocd-apps#327