cert-manager: Add dch-ca issuer

In-cluster services can now get certificates signed by the DCH CA via
`step-ca`.  This issuer uses ACME with the HTTP-01 challenge, so it
can only issue certificates for names in the _pyrocufflink.blue_ zone
that point to the ingress controllers.
This commit is contained in:
2024-07-26 20:49:00 -05:00
parent 54187176ba
commit e56a38c034
2 changed files with 18 additions and 0 deletions

View File

@@ -6,6 +6,7 @@ resources:
- cluster-issuer.yaml
- certificates.yaml
- cert-exporter.yaml
- dch-ca-issuer.yaml
secretGenerator:
- name: zerossl-eab