mirror of
https://github.com/michaelthomson0797/fleet-infra.git
synced 2026-02-04 13:09:53 +00:00
move cert and issuer to controllers
This commit is contained in:
@@ -0,0 +1,20 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: Certificate
|
||||
metadata:
|
||||
name: letsencrypt-wildcard-cert-michaelthomson.dev
|
||||
namespace: letsencrypt-wildcard-cert
|
||||
spec:
|
||||
# secretName doesn't have to match the certificate name, but it may as well, for simplicity!
|
||||
secretName: letsencrypt-wildcard-cert-michaelthomson.dev
|
||||
secretTemplate:
|
||||
annotations:
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: ""
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: ""
|
||||
issuerRef:
|
||||
name: letsencrypt-prod
|
||||
kind: ClusterIssuer
|
||||
dnsNames:
|
||||
- "michaelthomson.dev"
|
||||
- "*.michaelthomson.dev"
|
||||
@@ -0,0 +1,20 @@
|
||||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: letsencrypt-prod
|
||||
spec:
|
||||
acme:
|
||||
email: michael@michaelthomson.dev
|
||||
server: https://acme-v02.api.letsencrypt.org/directory
|
||||
privateKeySecretRef:
|
||||
name: letsencrypt-staging
|
||||
solvers:
|
||||
- selector:
|
||||
dnsZones:
|
||||
- "michaelthomson.dev"
|
||||
dns01:
|
||||
cloudflare:
|
||||
email: michael@michaelthomson.dev
|
||||
apiKeySecretRef:
|
||||
name: secret
|
||||
key: cloudflare_api_key
|
||||
13
infrastructure/controllers/cert-manager/secret.yaml
Normal file
13
infrastructure/controllers/cert-manager/secret.yaml
Normal file
@@ -0,0 +1,13 @@
|
||||
---
|
||||
apiVersion: bitnami.com/v1alpha1
|
||||
kind: SealedSecret
|
||||
metadata:
|
||||
name: secret
|
||||
namespace: cert-manager
|
||||
spec:
|
||||
encryptedData:
|
||||
cloudflare_api_key: AgCnbPF8qdEJkV70GZtytvOmQUHEF3KiN1UtxJGbmWopRc/OB3414xEXRfVmRJ5UJ64tb1IvokmWOwfXbd+RkiYuDJEv8TNHv4uzpmnOLghbbeUFSf10vp8jhiNGzKyRZGwfaPYU+x8Nje5t26CJgSS4DzhujtvBOczr+0GPV48Sj7kG7MVLk+Y5Khnq/4BiCBB71dsEJfvHBb3bjEe7LqCBMHUwtAZjunFd9YIg+Wd/ZiDj6rPZxhwyAchOoUUuPNumwsP2IYz8/IuneGCQMoW+pgN4GgJtk1IrQ5fn9p/IctFgY8QK06LPgXSlUj2/QLvvyXd4Ce/F1KNE5REhKVbywF60KdgtdgFnrfz7YN88vXcxDU33ikXdwF6Sk6TN0Of241Wb96H58U6l1lMqxaityl1Q6GYodsiB7j7b3eDEZBpHCFiQYZxdGfUKe2cC1fdO5EKGeRaN9pJnTtcNj5M7orqe4dinrLZZvJrhnjapxJk3opffJKerrOIDaYHoBIdGySfiirt0mZeYRTaiO2nECKRc6ohYBodlJD5ncYZxdgm5d4JzhDoaaen2jR2aAUrFNjWo5zDVLejiciP+vQ/Ed3M0RE+kxn5Ek17OjuMmdpNoOru5kydtCXE4uIouM9+qbDjCNebMbHCZMEjfT+Ulhr8pP6k3BCr0EgAIzFDVOBSVKUVowcuUhlEQrR2HWROANKSW/ltn6lc15vGcJ2dx19yV4g5BnMMalioVckpwfkcQLRL4
|
||||
template:
|
||||
metadata:
|
||||
name: secret
|
||||
namespace: cert-manager
|
||||
Reference in New Issue
Block a user