This commit is contained in:
Fang-Pen Lin
2025-11-24 14:26:23 -08:00
parent 681f7995cf
commit cdc1e7cc16
@@ -50,14 +50,17 @@ The following steps show how to install cert-manager (using `kubectl`) and obtai
</Step> </Step>
<Step title="Install cert-manager"> <Step title="Install cert-manager">
Install `cert-manager` into your Kubernetes cluster by following the instructions [here](https://cert-manager.io/docs/installation/) or by running the following command:
Install cert-manager in your Kubernetes cluster by following the official guide [here](https://cert-manager.io/docs/installation/) or by applying the manifest directly:
```bash ```bash
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.15.3/cert-manager.yaml kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.15.3/cert-manager.yaml
``` ```
</Step> </Step>
<Step title="Create Kubernetes Secret for the EAB secret of Infisical ACME server"> <Step title="Create a Kubernetes Secret for the Infisical ACME EAB credentials">
Start by creating a Kubernetes `Secret` containing the **EAB Secret** from step 1. As mentioned previously, this will be used by the Infisical PKI issuer to authenticate with Infisical. Create a Kubernetes `Secret` that contains the **EAB Secret (HMAC key)** obtained in step 1.
cert-manager uses this secret to authenticate with the Infisical ACME server via External Account Binding (EAB).
<Tabs> <Tabs>
<Tab title="kubectl command"> <Tab title="kubectl command">
@@ -83,6 +86,7 @@ The following steps show how to install cert-manager (using `kubectl`) and obtai
``` ```
</Tab> </Tab>
</Tabs> </Tabs>
</Step> </Step>
<Step title="Create the cert-manager Issuer connecting to Infisical ACME server"> <Step title="Create the cert-manager Issuer connecting to Infisical ACME server">
Next, create the cert-manager Issuer or ClusterIssuer by filling out `acme_server_url`, `your_email`, `acme_eab_kid`, and applying the following configuration file for the `Issuer` resource. Next, create the cert-manager Issuer or ClusterIssuer by filling out `acme_server_url`, `your_email`, `acme_eab_kid`, and applying the following configuration file for the `Issuer` resource.
@@ -142,6 +146,7 @@ The following steps show how to install cert-manager (using `kubectl`) and obtai
Also, currently Infisical ACME server only supports HTTP-01 and requires all the certificate orders passing the challenge before issuing certificates. Also, currently Infisical ACME server only supports HTTP-01 and requires all the certificate orders passing the challenge before issuing certificates.
We will allow users to opt-out challenge in the near future and also provide support DNS-01 as well. We will allow users to opt-out challenge in the near future and also provide support DNS-01 as well.
</Note> </Note>
</Step> </Step>
<Step title="Create Certificate"> <Step title="Create Certificate">
@@ -190,6 +195,7 @@ The following steps show how to install cert-manager (using `kubectl`) and obtai
NAME READY SECRET ISSUER STATUS AGE NAME READY SECRET ISSUER STATUS AGE
certificate-by-issuer True certificate-by-issuer issuer-infisical Certificate is up to date and has not expired 20h certificate-by-issuer True certificate-by-issuer issuer-infisical Certificate is up to date and has not expired 20h
``` ```
</Step> </Step>
<Step title="Use Certificate in Kubernetes Secret"> <Step title="Use Certificate in Kubernetes Secret">
Since the actual certificate and private key are stored in a Kubernetes secret, we can check that the secret was created successfully by running the following command: Since the actual certificate and private key are stored in a Kubernetes secret, we can check that the secret was created successfully by running the following command:
@@ -240,6 +246,7 @@ The following steps show how to install cert-manager (using `kubectl`) and obtai
``` ```
In any case, the certificate is ready to be used as Kubernetes Secret by your Kubernetes resources. In any case, the certificate is ready to be used as Kubernetes Secret by your Kubernetes resources.
</Step> </Step>
</Steps> </Steps>