fffc14f880
why: after #417 stood up the central Let's Encrypt *.unkin.net wildcard (Certificate wildcard-unkin-net, secret wildcard-unkin-net-tls, emberstack- reflected), the remaining single-label public hosts should terminate on the real publicly-trusted leaf instead of the internal Vault-PKI CA. A *.unkin.net wildcard only matches single-label subdomains, so cluster hostnames under *.k8s.syd1.au.unkin.net stay on vault-issuer. - certificate_wildcard-unkin-net: reflect the secret into arrstack, authentik and gitea (append to both reflector namespace lists) - arrstack: point the public arrproxy gateway (arrstack.unkin.net) at wildcard-unkin-net-tls and drop its vault-issuer annotations - authentik: point the identity.unkin.net listener at wildcard-unkin-net-tls; the identity.k8s.syd1.au.unkin.net listeners keep authentik-tls, so the gateway common-name is retargeted to the cluster host - gitea: secret reflected only; git.unkin.net cutover deferred (no manifest change), same deferred pattern as fafflix
28 lines
1.1 KiB
YAML
28 lines
1.1 KiB
YAML
---
|
|
# Single, centrally-managed Let's Encrypt *.unkin.net wildcard. DNS-01 validates
|
|
# once against the delegated _acme-challenge.unkin.net CNAME, so consumers get a
|
|
# real public leaf without per-host challenge records. The minted secret carries
|
|
# emberstack reflector annotations (via secretTemplate) so it is auto-reflected
|
|
# into consumer namespaces; append future consumers to the *-namespaces lists.
|
|
apiVersion: cert-manager.io/v1
|
|
kind: Certificate
|
|
metadata:
|
|
name: wildcard-unkin-net
|
|
namespace: cert-manager
|
|
spec:
|
|
secretName: wildcard-unkin-net-tls
|
|
secretTemplate:
|
|
annotations:
|
|
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
|
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea"
|
|
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
|
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea"
|
|
privateKey:
|
|
size: 4096
|
|
dnsNames:
|
|
- "*.unkin.net"
|
|
issuerRef:
|
|
name: letsencrypt
|
|
kind: ClusterIssuer
|
|
group: cert-manager.io
|