mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 23:27:14 +00:00
docs
This commit is contained in:
@@ -89,35 +89,35 @@ The following steps show how to install cert-manager (using `kubectl`) and obtai
|
|||||||
|
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Create the cert-manager Issuer connecting to Infisical ACME server">
|
<Step title="Create the cert-manager Issuer connecting to Infisical ACME server">
|
||||||
Next, create the cert-manager Issuer or ClusterIssuer by filling out `acme_server_url`, `your_email`, `acme_eab_kid`, and applying the following configuration file for the `Issuer` resource.
|
Next, create a cert-manager `Issuer` (or `ClusterIssuer`) by replacing the placeholders `<acme_server_url>`, `<your_email>`, and `<acme_eab_kid>` in the configuration below and applying it.
|
||||||
This configuration file specifies the connection details to your Infisical PKI CA to be used for issuing certificates.
|
This resource configures cert-manager to use your Infisical PKI collection's ACME server for certificate issuance.
|
||||||
|
|
||||||
```yaml infisical-issuer.yaml
|
```yaml infisical-issuer.yaml
|
||||||
apiVersion: cert-manager.io/v1
|
apiVersion: cert-manager.io/v1
|
||||||
kind: Issuer
|
kind: Issuer
|
||||||
metadata:
|
metadata:
|
||||||
name: issuer-infisical
|
name: issuer-infisical
|
||||||
|
namespace: <namespace_you_want_to_issue_certificates_in>
|
||||||
spec:
|
spec:
|
||||||
acme:
|
acme:
|
||||||
# the URL of your Infisical certificate profile with
|
# ACME server URL from your Infisical certificate profile (Step 1)
|
||||||
# ACME enrollment method from step 1
|
|
||||||
server: <acme_server_url>
|
server: <acme_server_url>
|
||||||
# your email address, any email could work.
|
# Email address for ACME account (any valid email works; currently ignored by Infisical)
|
||||||
# currently we just ignore the value
|
|
||||||
email: <your_email>
|
email: <your_email>
|
||||||
externalAccountBinding:
|
externalAccountBinding:
|
||||||
keyID: <acme_eab_kid> # the EAB secret value from step 1
|
# EAB Key ID from Step 1
|
||||||
keySecretRef: # reference to the Secret created in step 3
|
keyID: <acme_eab_kid>
|
||||||
name: "issuer-infisical-client-secret"
|
# Reference to the Kubernetes Secret containing the EAB HMAC key (created in Step 3)
|
||||||
key: "clientSecret"
|
keySecretRef:
|
||||||
|
name: issuer-infisical-client-secret
|
||||||
|
key: clientSecret
|
||||||
privateKeySecretRef:
|
privateKeySecretRef:
|
||||||
name: issuer-infisical-account-key
|
name: issuer-infisical-account-key
|
||||||
solvers:
|
solvers:
|
||||||
- http01:
|
- http01:
|
||||||
ingress:
|
ingress:
|
||||||
# this doesn't need to be nginx, you can use any
|
# Replace with your actual ingress class if different
|
||||||
# ingressClassName available in your Kubernetes cluster
|
className: nginx
|
||||||
ingressClassName: nginx
|
|
||||||
```
|
```
|
||||||
|
|
||||||
```
|
```
|
||||||
@@ -136,15 +136,10 @@ The following steps show how to install cert-manager (using `kubectl`) and obtai
|
|||||||
```
|
```
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
An `Issuer` is a namespaced resource, and it is not possible to issue certificates from an `Issuer` in a different namespace.
|
- Currently, the Infisical ACME server only supports the HTTP-01 challenge and requires successful challenge completion before issuing certificates. Support for optional challenges and DNS-01 is planned for a future release.
|
||||||
This means you will need to create an `Issuer` in each namespace you wish to obtain `Certificates` in.
|
- An `Issuer` is namespace-scoped. Certificates can only be issued using an `Issuer` that exists in the same namespace as the `Certificate` resource.
|
||||||
|
- If you need to issue certificates across multiple namespaces with a single resource, create a `ClusterIssuer` instead. The configuration is identical except `kind: ClusterIssuer` and no `metadata.namespace`.
|
||||||
If you want to create a single `Issuer` that can be consumed in multiple namespaces, you should consider creating a `ClusterIssuer` resource. This is almost identical to the `Issuer` resource, however is non-namespaced so it can be used to issue `Certificates` across all namespaces.
|
- More details: https://cert-manager.io/docs/configuration/acme/
|
||||||
|
|
||||||
You can read more about the `Issuer` and `ClusterIssuer` resources [here](https://cert-manager.io/docs/configuration/).
|
|
||||||
|
|
||||||
Also, currently Infisical ACME server only supports HTTP-01 and requires all the certificate orders passing the challenge before issuing certificates.
|
|
||||||
We will allow users to opt-out challenge in the near future and also provide support DNS-01 as well.
|
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
</Step>
|
</Step>
|
||||||
|
|||||||
Reference in New Issue
Block a user