2019-06-26 04:21:09 +03:00
|
|
|
# The following manifests contain a self-signed issuer CR and a certificate CR.
|
|
|
|
# More document can be found at https://docs.cert-manager.io
|
2019-12-12 02:52:48 +03:00
|
|
|
# WARNING: Targets CertManager 0.11 check https://docs.cert-manager.io/en/latest/tasks/upgrading/index.html for breaking changes
|
|
|
|
apiVersion: cert-manager.io/v1alpha2
|
2019-06-26 04:21:09 +03:00
|
|
|
kind: Issuer
|
|
|
|
metadata:
|
|
|
|
name: selfsigned-issuer
|
|
|
|
namespace: system
|
|
|
|
spec:
|
|
|
|
selfSigned: {}
|
|
|
|
---
|
2019-12-12 02:52:48 +03:00
|
|
|
apiVersion: cert-manager.io/v1alpha2
|
2019-06-26 04:21:09 +03:00
|
|
|
kind: Certificate
|
|
|
|
metadata:
|
|
|
|
name: serving-cert # this name should match the one appeared in kustomizeconfig.yaml
|
|
|
|
namespace: system
|
|
|
|
spec:
|
2019-12-12 02:52:48 +03:00
|
|
|
# $(SERVICE_NAME) and $(SERVICE_NAMESPACE) will be substituted by kustomize
|
2019-06-26 04:21:09 +03:00
|
|
|
dnsNames:
|
2019-12-12 02:52:48 +03:00
|
|
|
- $(SERVICE_NAME).$(SERVICE_NAMESPACE).svc
|
|
|
|
- $(SERVICE_NAME).$(SERVICE_NAMESPACE).svc.cluster.local
|
2019-06-26 04:21:09 +03:00
|
|
|
issuerRef:
|
|
|
|
kind: Issuer
|
|
|
|
name: selfsigned-issuer
|
|
|
|
secretName: webhook-server-cert # this secret will not be prefixed, since it's not managed by kustomize
|