--- # Serving cert off the internal Vault-PKI CA (agents already trust vault-ca-cert). # SANs cover the GitHub endpoints ghp impersonates plus its own management host. apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: ghp-tls namespace: ghp labels: app.kubernetes.io/name: ghp app.kubernetes.io/instance: ghp annotations: argocd.argoproj.io/sync-wave: "0" spec: secretName: ghp-tls issuerRef: kind: ClusterIssuer name: vault-issuer commonName: ghp.k8s.syd1.au.unkin.net dnsNames: - github.com - api.github.com - codeload.github.com - "*.githubcopilot.com" - ghp.k8s.syd1.au.unkin.net privateKey: algorithm: RSA size: 4096