feat: updated doc for k8s issuer

This commit is contained in:
=
2025-05-30 17:53:21 +00:00
committed by Akhil Mohan
parent 3a0e2bf88b
commit 3362ec29cd
3 changed files with 84 additions and 50 deletions
+60 -14
View File
@@ -21,8 +21,9 @@ A typical workflow for using the Infisical PKI Issuer to issue certificates for
3. Installing `cert-manager` into your Kubernetes cluster. 3. Installing `cert-manager` into your Kubernetes cluster.
4. Installing the Infisical PKI Issuer controller into your Kubernetes cluster. 4. Installing the Infisical PKI Issuer controller into your Kubernetes cluster.
5. Creating an `Issuer` or `ClusterIssuer` resource in your Kubernetes cluster to represent the Infisical PKI issuer you wish to use. 5. Creating an `Issuer` or `ClusterIssuer` resource in your Kubernetes cluster to represent the Infisical PKI issuer you wish to use.
6. Creating a `Certificate` resource in your Kubernetes cluster to represent a certificate you wish to issue. As part of this step, you specify the Kubernetes `Secret` to create and store the issued certificate and private key. 6. Create an the approver policy to accept certificate request.
7. Consuming the issued certificate across your Kubernetes resources from the specified Kubernetes `Secret`. 7. Creating a `Certificate` resource in your Kubernetes cluster to represent a certificate you wish to issue. As part of this step, you specify the Kubernetes `Secret` to create and store the issued certificate and private key.
8. Consuming the issued certificate across your Kubernetes resources from the specified Kubernetes `Secret`.
## Guide ## Guide
@@ -84,7 +85,7 @@ In the following steps, we explore how to install the Infisical PKI Issuer using
</Tabs> </Tabs>
</Step> </Step>
<Step title="Create Infisical PKI Issuer"> <Step title="Create Infisical PKI Issuer">
Next, create the Infisical PKI Issuer by filling out `url`, `clientId`, either `caId` or `certificateTemplateId`, and applying the following configuration file for the `Issuer` resource. Next, create the Infisical PKI Issuer by filling out `url`, `clientId`, `projectId` or `certificateTemplateName`, and applying the following configuration file for the `Issuer` resource.
This configuration file specifies the connection details to your Infisical PKI CA to be used for issuing certificates. This configuration file specifies the connection details to your Infisical PKI CA to be used for issuing certificates.
```yaml infisical-issuer.yaml ```yaml infisical-issuer.yaml
@@ -95,8 +96,8 @@ In the following steps, we explore how to install the Infisical PKI Issuer using
namespace: <namespace_you_want_to_issue_certificates_in> namespace: <namespace_you_want_to_issue_certificates_in>
spec: spec:
url: "https://app.infisical.com" # the URL of your Infisical instance url: "https://app.infisical.com" # the URL of your Infisical instance
caId: <ca_id> # the ID of the CA you want to use to issue certificates projectId: <project_id> # the ID of the project you want to use to issue certificates
certificateTemplateId: <certificate_template_id> # the ID of the certificate template you want to use to issue certificates against certificateTemplateName: <certificate_template_name> # the name of the certificate template you want to use to issue certificates against
authentication: authentication:
universalAuth: universalAuth:
clientId: <client_id> # the Client ID from step 1 clientId: <client_id> # the Client ID from step 1
@@ -109,15 +110,6 @@ In the following steps, we explore how to install the Infisical PKI Issuer using
kubectl apply -f infisical-issuer.yaml kubectl apply -f infisical-issuer.yaml
``` ```
<Warning>
The Infisical PKI Issuer supports issuing certificates against a specific CA or a specific certificate template.
For this reason, you should only fill in the `caId` or the `certificateTemplateId` field but not both.
We recommend using the `certificateTemplateId` field to issue certificates against a specific [certificate template](/documentation/platform/pki/certificate-templates)
since templates let you enforce constraints on issued certificates and may have alerting policies bound to them.
</Warning>
You can check that the issuer was created successfully by running the following command: You can check that the issuer was created successfully by running the following command:
```bash ```bash
@@ -138,6 +130,50 @@ In the following steps, we explore how to install the Infisical PKI Issuer using
You can read more about the `Issuer` and `ClusterIssuer` resources [here](https://cert-manager.io/docs/configuration/). You can read more about the `Issuer` and `ClusterIssuer` resources [here](https://cert-manager.io/docs/configuration/).
</Note> </Note>
</Step> </Step>
<Step title="Create Approver Policy">
If you create a `CertificateRequest` now, you'll notice it's neither approved nor denied. This is expected because by default cert-manager approver controller requires an approver-policy.
To enable approval, create the following YAML file and apply it:
```yaml infisical-approver-policy.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: infisical-issuer-approver
rules:
# Permission to approve or deny CertificateRequests for signers in cert-manager.io API group
- apiGroups: ['cert-manager.io']
resources: ['signers']
verbs: ['approve']
resourceNames:
# Grant approval permissions for namespaced issuers
- "issuers.infisical-issuer.infisical.com/default.issuer-infisical"
# Grant approval permissions for cluster-scoped issuers
- "clusterissuers.infisical-issuer.infisical.com/clusterissuer-infisical"
---
# Bind the cert-manager service account to the new role
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: infisical-issuer-approver-binding
subjects:
- kind: ServiceAccount
name: cert-manager
namespace: cert-manager
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: infisical-issuer-approver
```
```
kubectl apply -f infisical-approver-policy.yaml
```
This configuration creates a `ClusterRole` named `infisical-issuer-approver` that grants approval permissions for specific Infisical issuer types. It then binds this role to the cert-manager service account, allowing it to approve certificate requests from your Infisical issuers.
For information, check out [cert manager approval policy doc](https://cert-manager.io/docs/policy/approval/approver-policy/).
</Step>
<Step title="Create Certificate"> <Step title="Create Certificate">
Finally, create a `Certificate` by applying the following configuration file. Finally, create a `Certificate` by applying the following configuration file.
@@ -229,6 +265,7 @@ In the following steps, we explore how to install the Infisical PKI Issuer using
In any case, the certificate is ready to be used as Kubernetes Secret by your Kubernetes resources. In any case, the certificate is ready to be used as Kubernetes Secret by your Kubernetes resources.
</Step> </Step>
</Steps> </Steps>
## FAQ ## FAQ
@@ -240,11 +277,20 @@ In the following steps, we explore how to install the Infisical PKI Issuer using
<Note> <Note>
Currently, not all fields are supported by the Infisical PKI Issuer. Currently, not all fields are supported by the Infisical PKI Issuer.
</Note> </Note>
</Accordion> </Accordion>
<Accordion title="Can certificates be renewed automatically?"> <Accordion title="Can certificates be renewed automatically?">
Yes. `cert-manager` will automatically renew certificates according to the `renewBefore` threshold of expiry as Yes. `cert-manager` will automatically renew certificates according to the `renewBefore` threshold of expiry as
specified in the corresponding `Certificate` resource. specified in the corresponding `Certificate` resource.
You can read more about the `renewBefore` field [here](https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.CertificateSpec). You can read more about the `renewBefore` field [here](https://cert-manager.io/docs/reference/api-docs/#cert-manager.io/v1.CertificateSpec).
</Accordion>
<Accordion title="Why is my CertificateRequest not being approved, showing 'CertificateRequest has not been approved yet. Ignoring.'?">
If you see log messages similar to:
```
"CertificateRequest has not been approved yet. Ignoring.","controller":"certificaterequest","controllerGroup":"cert-manager.io","controllerKind":"CertificateRequest","CertificateRequest":{"name":"skynet-infisical-rta-rsa2048-1","namespace":"infisical-system"},"namespace":"infisical-system","name":"skynet-infisical-rta-rsa2048-1","reconcileID":"bfb7cad9-d867-45b5-b3a3-0139e731b7a6"}
```
This indicates that the `CertificateRequest` has been created, but `cert-manager` has not yet approved it. This typically occurs because a necessary approver policy is missing. Refer to the documentation above to create an approver policy.
</Accordion> </Accordion>
</AccordionGroup> </AccordionGroup>
@@ -23,7 +23,6 @@ import { usePopUp } from "@app/hooks/usePopUp";
import { CaInstallCertModal } from "../CertificateAuthoritiesPage/components/CaInstallCertModal"; import { CaInstallCertModal } from "../CertificateAuthoritiesPage/components/CaInstallCertModal";
import { CaModal } from "../CertificateAuthoritiesPage/components/CaModal"; import { CaModal } from "../CertificateAuthoritiesPage/components/CaModal";
import { CertificateTemplatesSection } from "../CertificatesPage/components/CertificateTemplatesSection";
import { import {
CaCertificatesSection, CaCertificatesSection,
CaCrlsSection, CaCrlsSection,
@@ -126,7 +125,6 @@ const Page = () => {
</div> </div>
<div className="w-full"> <div className="w-full">
<CaCertificatesSection caId={data.id} /> <CaCertificatesSection caId={data.id} />
<CertificateTemplatesSection caId={data.id} />
<CaCrlsSection caId={data.id} /> <CaCrlsSection caId={data.id} />
</div> </div>
</div> </div>
@@ -2,7 +2,6 @@ import { useState } from "react";
import { Helmet } from "react-helmet"; import { Helmet } from "react-helmet";
import { useTranslation } from "react-i18next"; import { useTranslation } from "react-i18next";
import { import {
faArrowUpRightFromSquare,
faCertificate, faCertificate,
faEllipsis, faEllipsis,
faPencil, faPencil,
@@ -107,15 +106,6 @@ export const PkiTemplateListPage = () => {
<div className="mb-4 flex justify-between"> <div className="mb-4 flex justify-between">
<p className="text-xl font-semibold text-mineshaft-100">Templates</p> <p className="text-xl font-semibold text-mineshaft-100">Templates</p>
<div className="flex w-full justify-end"> <div className="flex w-full justify-end">
<a target="_blank" rel="noopener noreferrer">
<span className="flex w-max cursor-pointer items-center rounded-md border border-mineshaft-500 bg-mineshaft-600 px-4 py-2 text-mineshaft-200 duration-200 hover:border-primary/40 hover:bg-primary/10 hover:text-white">
Documentation{" "}
<FontAwesomeIcon
icon={faArrowUpRightFromSquare}
className="mb-[0.06rem] ml-1 text-xs"
/>
</span>
</a>
<ProjectPermissionCan <ProjectPermissionCan
I={ProjectPermissionPkiTemplateActions.Create} I={ProjectPermissionPkiTemplateActions.Create}
a={ProjectPermissionSub.CertificateTemplates} a={ProjectPermissionSub.CertificateTemplates}