Cert-Manager

cert-manager is an open-source, cloud-native Kubernetes controller that automates the issuance, renewal, and management of X.509 TLS certificates for workloads within a cluster.

By automatically handling certificate lifecycles, cert-manager reduces the administrative burden on developers and prevents service outages caused by expired certificates, ensuring that Kubernetes secrets containing certificates are always up-to-date.

Install

cert-manager is deployed via an OpenShift Operator from OKDerators.

Prerequisites

  1. Create the OKDerators CatalogSource

    Apply the following YAML configuration to your cluster. This configures the marketplace operator to pull operator metadata from the public OKDerators registry.

    apiVersion: operators.coreos.com/v1alpha1
    kind: CatalogSource
    metadata:
      name: okderators-catalog
      namespace: openshift-marketplace
    spec:
      sourceType: grpc
      image: quay.io/okderators/catalog-index:latest
      displayName: OKDerators
      publisher: OKDerators
      updateStrategy:
        registryPoll:
          interval: 10m   
    

Operator

Once the catalog is available, you can install cert-manager from the OpenShift GUI -> Ecosystem, or command-line.

  1. Create the operator namespace

    apiVersion: v1
    kind: Namespace
    metadata:
      name: cert-manager-operator
    
  2. Create the operator group

    apiVersion: operators.coreos.com/v1
    kind: OperatorGroup
    metadata:
      name: cert-manager-operator
      namespace: cert-manager-operator
    spec:
      upgradeStrategy: Default
    
    3. Enable the subscription to install the operator

    apiVersion: operators.coreos.com/v1alpha1
    kind: Subscription
    metadata:
      labels:
        operators.coreos.com/cert-manager-operator.cert-manager-operator: ""
      name: cert-manager-operator
      namespace: cert-manager-operator
    spec:
      channel: alpha
      installPlanApproval: Automatic
      name: cert-manager-operator
      source: okderators
      sourceNamespace: openshift-marketplace
    

Configuration

Once the operator is installed, we can define an instance of cert-manager and configure the cloudflare webhook

  1. Create the cert-manager instance

    apiVersion: operator.openshift.io/v1alpha1
    kind: CertManager
    metadata:
      name: cluster
    spec:
      controllerConfig:
        overrideArgs:
        - --dns01-recursive-nameservers-only
        - --dns01-recursive-nameservers=192.168.47.55:53
      logLevel: Normal
      managementState: Managed
      observedConfig: null
      operatorLogLevel: Normal
      unsupportedConfigOverrides: null
    
  2. Create a secret containing the cloudflare api key

    apiVersion: v1
    stringData:
      api-token: <cloudflare_api_key>
    kind: Secret
    metadata:
      name: cloudflare-api-token
      namespace: cert-manager
    type: Opaque
    
  3. Define the webhook for the DNS-01 integration

    apiVersion: cert-manager.io/v1
    kind: ClusterIssuer
    metadata:
      name: letsencrypt-cloudflare
    spec:
      acme:
        email: randal@endofday.com
        privateKeySecretRef:
          name: letsencrypt-cloudflare-account-key
        server: https://acme-v02.api.letsencrypt.org/directory
        solvers:
        - dns01:
            cloudflare:
              apiTokenSecretRef:
                key: api-token
                name: cloudflare-api-token
    

Testing

Generate A Certificate