feat: add ClusterIssuer letsencrypt-mareshq
This issuer has the connection to Cloudflare for DNS ACME challenge
This commit is contained in:
parent
152d191adc
commit
c77b0de063
6 changed files with 22 additions and 8 deletions
|
|
@ -25,7 +25,7 @@ argo-cd:
|
|||
- argocd.cloud.mareshq.com
|
||||
ingressClassName: nginx
|
||||
annotations:
|
||||
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||
cert-manager.io/cluster-issuer: letsencrypt-mareshq
|
||||
kubernetes.io/tls-acme: "true"
|
||||
nginx.ingress.kubernetes.io/server-snippet: |
|
||||
proxy_ssl_verify off;
|
||||
|
|
|
|||
|
|
@ -10,7 +10,7 @@ vault:
|
|||
enabled: true
|
||||
ingressClassName: nginx
|
||||
annotations:
|
||||
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||
cert-manager.io/cluster-issuer: letsencrypt-mareshq
|
||||
pathType: Prefix
|
||||
tls:
|
||||
- secretName: vault-tls
|
||||
|
|
|
|||
|
|
@ -1,13 +1,13 @@
|
|||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: letsencrypt-prod
|
||||
name: letsencrypt-mareshq
|
||||
spec:
|
||||
acme:
|
||||
email: me+infra@vojtechmares.com
|
||||
server: https://acme-v02.api.letsencrypt.org/directory
|
||||
privateKeySecretRef:
|
||||
name: letsencrypt-prod
|
||||
name: letsencrypt-mareshq
|
||||
solvers:
|
||||
- http01:
|
||||
ingress:
|
||||
|
|
@ -0,0 +1,14 @@
|
|||
apiVersion: cert-manager.io/v1
|
||||
kind: ClusterIssuer
|
||||
metadata:
|
||||
name: letsencrypt-prod
|
||||
spec:
|
||||
acme:
|
||||
email: me+infra@vojtechmares.com
|
||||
server: https://acme-v02.api.letsencrypt.org/directory
|
||||
privateKeySecretRef:
|
||||
name: letsencrypt-prod
|
||||
solvers:
|
||||
- http01:
|
||||
ingress:
|
||||
class: nginx
|
||||
|
|
@ -7,4 +7,4 @@ longhorn:
|
|||
tlsSecret: longhorn-tls
|
||||
|
||||
annotations:
|
||||
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||
cert-manager.io/cluster-issuer: letsencrypt-mareshq
|
||||
|
|
|
|||
|
|
@ -21,7 +21,7 @@ kube-prometheus-stack:
|
|||
enabled: true
|
||||
pathType: Prefix
|
||||
annotations:
|
||||
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||
cert-manager.io/cluster-issuer: letsencrypt-mareshq
|
||||
# nginx.ingress.kubernetes.io/auth-url: "https://auth.cloud.mareshq.com/oauth2/auth"
|
||||
# nginx.ingress.kubernetes.io/auth-signin: "https://auth.cloud.mareshq.com/oauth2/start?rd=$scheme://$host$request_uri"
|
||||
hosts:
|
||||
|
|
@ -47,7 +47,7 @@ kube-prometheus-stack:
|
|||
enabled: true
|
||||
pathType: Prefix
|
||||
annotations:
|
||||
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||
cert-manager.io/cluster-issuer: letsencrypt-mareshq
|
||||
hosts:
|
||||
- grafana.cloud.mareshq.com
|
||||
paths:
|
||||
|
|
@ -87,7 +87,7 @@ kube-prometheus-stack:
|
|||
enabled: true
|
||||
pathType: Prefix
|
||||
annotations:
|
||||
cert-manager.io/cluster-issuer: letsencrypt-prod
|
||||
cert-manager.io/cluster-issuer: letsencrypt-mareshq
|
||||
# nginx.ingress.kubernetes.io/auth-url: "https://auth.cloud.mareshq.com/oauth2/auth"
|
||||
# nginx.ingress.kubernetes.io/auth-signin: "https://auth.cloud.mareshq.com/oauth2/start?rd=$scheme://$host$request_uri"
|
||||
hosts:
|
||||
|
|
|
|||
Reference in a new issue