f37749523d
The haproxy edge terminates TLS for hosts under `main.unkin.net` and `ceph.unkin.net`, which the single `*.unkin.net` wildcard does not cover. - Add cert-manager Certificates for both wildcards from the `letsencrypt` ClusterIssuer. - Reflect the minted secrets into the `haproxy` namespace. Needs these records in the public unkin.net zone first: `_acme-challenge.main.unkin.net. CNAME _acme-challenge.main.acme.unkin.net.` `_acme-challenge.ceph.unkin.net. CNAME _acme-challenge.ceph.acme.unkin.net.` Reviewed-on: #484 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
17 lines
441 B
YAML
17 lines
441 B
YAML
---
|
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
|
|
resources:
|
|
- namespace.yaml
|
|
- serviceaccount.yaml
|
|
- clusterrole.yaml
|
|
- clusterrolebinding.yaml
|
|
- clusterissuer_vault-issuer.yaml
|
|
- vmservicescrape.yaml
|
|
- clusterissuer_letsencrypt.yaml
|
|
- clusterissuer_letsencrypt-staging.yaml
|
|
- certificate_wildcard-unkin-net.yaml
|
|
- certificate_wildcard-main-unkin-net.yaml
|
|
- certificate_wildcard-ceph-unkin-net.yaml
|