f37749523d
The haproxy edge terminates TLS for hosts under `main.unkin.net` and `ceph.unkin.net`, which the single `*.unkin.net` wildcard does not cover. - Add cert-manager Certificates for both wildcards from the `letsencrypt` ClusterIssuer. - Reflect the minted secrets into the `haproxy` namespace. Needs these records in the public unkin.net zone first: `_acme-challenge.main.unkin.net. CNAME _acme-challenge.main.acme.unkin.net.` `_acme-challenge.ceph.unkin.net. CNAME _acme-challenge.ceph.acme.unkin.net.` Reviewed-on: #484 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
27 lines
942 B
YAML
27 lines
942 B
YAML
---
|
|
# Let's Encrypt *.main.unkin.net wildcard for the haproxy edge (pve, arr stack,
|
|
# jellyfin, stalwart webadmin/autoconfig). DNS-01 needs the delegated
|
|
# _acme-challenge.main.unkin.net CNAME in the public unkin.net zone.
|
|
# _acme-challenge.main.unkin.net. CNAME _acme-challenge.main.acme.unkin.net.
|
|
apiVersion: cert-manager.io/v1
|
|
kind: Certificate
|
|
metadata:
|
|
name: wildcard-main-unkin-net
|
|
namespace: cert-manager
|
|
spec:
|
|
secretName: wildcard-main-unkin-net-tls
|
|
secretTemplate:
|
|
annotations:
|
|
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
|
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "haproxy"
|
|
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
|
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "haproxy"
|
|
privateKey:
|
|
size: 4096
|
|
dnsNames:
|
|
- "*.main.unkin.net"
|
|
issuerRef:
|
|
name: letsencrypt
|
|
kind: ClusterIssuer
|
|
group: cert-manager.io
|