Cert-Manager¶
cert-manager is an open-source, cloud-native Kubernetes controller that automates the issuance, renewal, and management of X.509 TLS certificates for workloads within a cluster.
By automatically handling certificate lifecycles, cert-manager reduces the administrative burden on developers and prevents service outages caused by expired certificates, ensuring that Kubernetes secrets containing certificates are always up-to-date.
Install¶
cert-manager is deployed via an OpenShift Operator from OKDerators.
Prerequisites¶
-
Create the OKDerators CatalogSource
Apply the following YAML configuration to your cluster. This configures the marketplace operator to pull operator metadata from the public OKDerators registry.apiVersion: operators.coreos.com/v1alpha1 kind: CatalogSource metadata: name: okderators-catalog namespace: openshift-marketplace spec: sourceType: grpc image: quay.io/okderators/catalog-index:latest displayName: OKDerators publisher: OKDerators updateStrategy: registryPoll: interval: 10m
Operator¶
Once the catalog is available, you can install cert-manager from the OpenShift GUI -> Ecosystem, or command-line.
-
Create the operator namespace
apiVersion: v1 kind: Namespace metadata: name: cert-manager-operator -
Create the operator group
3. Enable the subscription to install the operatorapiVersion: operators.coreos.com/v1 kind: OperatorGroup metadata: name: cert-manager-operator namespace: cert-manager-operator spec: upgradeStrategy: DefaultapiVersion: operators.coreos.com/v1alpha1 kind: Subscription metadata: labels: operators.coreos.com/cert-manager-operator.cert-manager-operator: "" name: cert-manager-operator namespace: cert-manager-operator spec: channel: alpha installPlanApproval: Automatic name: cert-manager-operator source: okderators sourceNamespace: openshift-marketplace
Configuration¶
Once the operator is installed, we can define an instance of cert-manager and configure the cloudflare webhook
-
Create the cert-manager instance
apiVersion: operator.openshift.io/v1alpha1 kind: CertManager metadata: name: cluster spec: controllerConfig: overrideArgs: - --dns01-recursive-nameservers-only - --dns01-recursive-nameservers=192.168.47.55:53 logLevel: Normal managementState: Managed observedConfig: null operatorLogLevel: Normal unsupportedConfigOverrides: null -
Create a secret containing the cloudflare api key
apiVersion: v1 stringData: api-token: <cloudflare_api_key> kind: Secret metadata: name: cloudflare-api-token namespace: cert-manager type: Opaque -
Define the webhook for the DNS-01 integration
apiVersion: cert-manager.io/v1 kind: ClusterIssuer metadata: name: letsencrypt-cloudflare spec: acme: email: randal@endofday.com privateKeySecretRef: name: letsencrypt-cloudflare-account-key server: https://acme-v02.api.letsencrypt.org/directory solvers: - dns01: cloudflare: apiTokenSecretRef: key: api-token name: cloudflare-api-token