Skip to content

Commit 1438c6c

Browse files
Let's see if I can make a sub-sub-domain cert
1 parent 3ebdb5f commit 1438c6c

File tree

3 files changed

+44
-26
lines changed

3 files changed

+44
-26
lines changed
Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
---
2+
apiVersion: cert-manager.io/v1
3+
kind: Certificate
4+
metadata:
5+
name: "infra.franta.us-production"
6+
spec:
7+
secretName: "infra.franta.us-production-tls"
8+
issuerRef:
9+
name: letsencrypt-production
10+
kind: ClusterIssuer
11+
commonName: "infra.franta.us"
12+
dnsNames:
13+
- "infra.franta.us"
14+
- "*.infra.franta.us"
15+
---
16+
# yaml-language-server: $schema=https://kubernetes-schemas.pages.dev/external-secrets.io/pushsecret_v1alpha1.json
17+
apiVersion: external-secrets.io/v1alpha1
18+
kind: PushSecret
19+
metadata:
20+
name: &name infra-franta-us-tls
21+
spec:
22+
secretStoreRefs:
23+
- name: akeyless-secret-store
24+
kind: ClusterSecretStore
25+
selector:
26+
secret:
27+
name: infra.franta.us-production-tls
28+
template:
29+
engineVersion: v2
30+
data:
31+
tls.crt: '{{ index . "tls.crt" | b64enc }}'
32+
tls.key: '{{ index . "tls.key" | b64enc }}'
33+
data:
34+
- match:
35+
secretKey: &key tls.crt
36+
remoteRef:
37+
remoteKey: *name
38+
property: *key
39+
- match:
40+
secretKey: &key tls.key
41+
remoteRef:
42+
remoteKey: *name
43+
property: *key

kubernetes/apps/cert-manager/cert-manager/issuers/kustomization.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,3 +5,4 @@ resources:
55
- ./externalsecret.yaml
66
- ./issuers.yaml
77
- ./ca.yaml
8+
- ./infra-certificate.yaml

kubernetes/apps/cert-manager/cert-manager/issuers/secret.sops.yaml

Lines changed: 0 additions & 26 deletions
This file was deleted.

0 commit comments

Comments
 (0)