Skip to content

Conversation

@rmvangun
Copy link
Contributor

@rmvangun rmvangun commented Feb 5, 2025

Establishes a private CA for signing keys internally on the cluster. This is necessary for services, in particular etcd+external-dns, that are not able to use unsigned certs.

Trust manager is also used to copy certs in to appropriate namespaces. A kyverno mutating webhook allows automatically injecting the CA in to pods.

@rmvangun rmvangun merged commit 68cbd15 into main Feb 5, 2025
9 checks passed
@rmvangun rmvangun deleted the ENG-213_Support-for-certificate-authority branch February 5, 2025 14:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants