The clouddns approach is dropped in favour of self-delegating the ACME
challenge to our own BIND: a one-time CNAME sends _acme-challenge.unkin.net
into acme.unkin.net (served by bind-external), and cert-manager solves DNS-01
via RFC2136+TSIG against it. No GCP service account or Vault KV secret needed.
- Replace the dns01 clouddns solver in both ClusterIssuers with rfc2136
(nameserver 198.18.199.53:53, key certmanager, HMACSHA256, secret
certmanager-tsig reflected into the cert-manager namespace).
- Remove the now-unneeded VaultAuth, VaultStaticSecret and clouddns
ServiceAccount.
Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
unkin.net public DNS is delegated to Google Cloud DNS, so publicly-trusted
wildcard certs need an ACME issuer using cert-manager's clouddns DNS-01
solver. The existing vault-issuer (internal PKI) is unchanged.
- Add ClusterIssuers letsencrypt (prod) and letsencrypt-staging, both using
a dns01 clouddns solver with a GCP service-account key.
- Sync that key from Vault KV into Secret cert-manager-clouddns via a
VaultStaticSecret + VaultAuth (role cert_manager_clouddns) and a dedicated
cert-manager-clouddns service account.
- Wire the new files into the base kustomization.
- Whitelist cert-manager.io ClusterIssuer in the platform AppProject.
The clouddns project and the KV secret value are set out-of-band.
Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT