Cert-Manager
create ClusterIssuer
apiVersion: v1
kind: Secret
metadata:
name: tsig-secret
type: Opaque
data:
tsig-secret-key: S3pxxxxxQ==
---
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: dns-issuer-rfc2136-live
spec:
acme:
server: https://acme-v02.api.letsencrypt.org/directory
email: 'teamsmiley@gmail.com'
privateKeySecretRef:
name: dns-issuer-rfc2136-live
solvers:
- dns01:
rfc2136:
nameserver: 172.21.1.20:53
tsigKeyName: teamsmiley-dev-secret
tsigAlgorithm: HMACSHA512
tsigSecretSecretRef:
name: tsig-secret
key: tsig-secret-keyIngress에서 사용
Last updated