This commit is contained in:
Fang-Pen Lin
2025-11-24 14:26:23 -08:00
parent 681f7995cf
commit cdc1e7cc16
@@ -50,14 +50,17 @@ The following steps show how to install cert-manager (using `kubectl`) and obtai
</Step>
<Step title="Install cert-manager">
Install `cert-manager` into your Kubernetes cluster by following the instructions [here](https://cert-manager.io/docs/installation/) or by running the following command:
Install cert-manager in your Kubernetes cluster by following the official guide [here](https://cert-manager.io/docs/installation/) or by applying the manifest directly:
```bash
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.15.3/cert-manager.yaml
```
</Step>
<Step title="Create Kubernetes Secret for the EAB secret of Infisical ACME server">
Start by creating a Kubernetes `Secret` containing the **EAB Secret** from step 1. As mentioned previously, this will be used by the Infisical PKI issuer to authenticate with Infisical.
<Step title="Create a Kubernetes Secret for the Infisical ACME EAB credentials">
Create a Kubernetes `Secret` that contains the **EAB Secret (HMAC key)** obtained in step 1.
cert-manager uses this secret to authenticate with the Infisical ACME server via External Account Binding (EAB).
<Tabs>
<Tab title="kubectl command">
@@ -83,6 +86,7 @@ The following steps show how to install cert-manager (using `kubectl`) and obtai
```
</Tab>
</Tabs>
</Step>
<Step title="Create the cert-manager Issuer connecting to Infisical ACME server">
Next, create the cert-manager Issuer or ClusterIssuer by filling out `acme_server_url`, `your_email`, `acme_eab_kid`, and applying the following configuration file for the `Issuer` resource.
@@ -142,6 +146,7 @@ The following steps show how to install cert-manager (using `kubectl`) and obtai
Also, currently Infisical ACME server only supports HTTP-01 and requires all the certificate orders passing the challenge before issuing certificates.
We will allow users to opt-out challenge in the near future and also provide support DNS-01 as well.
</Note>
</Step>
<Step title="Create Certificate">
@@ -190,6 +195,7 @@ The following steps show how to install cert-manager (using `kubectl`) and obtai
NAME READY SECRET ISSUER STATUS AGE
certificate-by-issuer True certificate-by-issuer issuer-infisical Certificate is up to date and has not expired 20h
```
</Step>
<Step title="Use Certificate in Kubernetes Secret">
Since the actual certificate and private key are stored in a Kubernetes secret, we can check that the secret was created successfully by running the following command:
@@ -240,6 +246,7 @@ The following steps show how to install cert-manager (using `kubectl`) and obtai
```
In any case, the certificate is ready to be used as Kubernetes Secret by your Kubernetes resources.
</Step>
</Steps>