Skip to content

Commit

Permalink
feat(kube-nas): setup cert-manager
Browse files Browse the repository at this point in the history
  • Loading branch information
tyriis committed Oct 15, 2023
1 parent 5d82e79 commit 0fcafae
Show file tree
Hide file tree
Showing 9 changed files with 172 additions and 0 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
---
# yaml-language-server: $schema=https://raw.githubusercontent.com/fluxcd-community/flux2-schemas/main/helmrelease-helm-v2beta1.json
apiVersion: helm.toolkit.fluxcd.io/v2beta1
kind: HelmRelease
metadata:
name: cert-manager
spec:
interval: 30m
chart:
spec:
chart: cert-manager
version: v1.13.1
sourceRef:
kind: HelmRepository
name: jetstack-charts
namespace: flux-system
interval: 30m
install:
crds: CreateReplace
remediation:
retries: 5
upgrade:
crds: CreateReplace
remediation:
retries: 5
values:
installCRDs: true
webhook:
enabled: true
extraArgs:
- --dns01-recursive-nameservers=1.1.1.1:53,9.9.9.9:53
- --dns01-recursive-nameservers-only
- --enable-certificate-owner-ref
replicaCount: 1
podDnsPolicy: "None"
podDnsConfig:
nameservers:
- "1.1.1.1"
- "9.9.9.9"
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
# yaml-language-server: $schema=https://json.schemastore.org/kustomization
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: cert-manager
resources:
- helm-release.yaml
32 changes: 32 additions & 0 deletions kubernetes/kube-nas/apps/cert-manager/cert-manager/flux-sync.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
---
# yaml-language-server: $schema=https://raw.githubusercontent.com/fluxcd-community/flux2-schemas/main/kustomization-kustomize-v1beta2.json
apiVersion: kustomize.toolkit.fluxcd.io/v1beta2
kind: Kustomization
metadata:
name: apps-cert-manager
namespace: flux-system
spec:
interval: 10m
path: ./kubernetes/talos-flux/apps/cert-manager/cert-manager/app
prune: true
sourceRef:
kind: GitRepository
name: home-ops
wait: true
---
# yaml-language-server: $schema=https://raw.githubusercontent.com/fluxcd-community/flux2-schemas/main/kustomization-kustomize-v1beta2.json
apiVersion: kustomize.toolkit.fluxcd.io/v1beta2
kind: Kustomization
metadata:
name: apps-cert-manager-issuers
namespace: flux-system
spec:
interval: 10m
path: ./kubernetes/talos-flux/apps/cert-manager/cert-manager/issuers
prune: true
sourceRef:
kind: GitRepository
name: home-ops
wait: true
dependsOn:
- name: apps-cert-manager
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
---
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt-production
spec:
acme:
server: https://acme-v02.api.letsencrypt.org/directory
email: "${SECRET_CLOUDFLARE_EMAIL}"
# preferredChain: ISRG Root X1
privateKeySecretRef:
name: letsencrypt-production
solvers:
- dns01:
cloudflare:
email: "${SECRET_CLOUDFLARE_EMAIL}"
apiKeySecretRef:
name: cloudflare-api-key
key: api-key
selector:
dnsZones:
- ${SECRET_DOMAIN}
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
---
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt-staging
spec:
acme:
server: https://acme-staging-v02.api.letsencrypt.org/directory
email: "${SECRET_CLOUDFLARE_EMAIL}"
privateKeySecretRef:
name: letsencrypt-staging
solvers:
- dns01:
cloudflare:
email: "${SECRET_CLOUDFLARE_EMAIL}"
apiKeySecretRef:
name: cloudflare-api-key
key: api-key
selector:
dnsZones:
- ${SECRET_DOMAIN}
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
---
# yaml-language-server: $schema=https://json.schemastore.org/kustomization
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: cert-manager
resources:
- secret.sops.yaml
- cluster-issuer-staging.yaml
- cluster-issuer-production.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
# yamllint disable
apiVersion: v1
kind: Secret
metadata:
name: cloudflare-api-key
stringData:
api-key: ENC[AES256_GCM,data:lMndRwfv1J1eo2+iTt5J4wstjrHI1XsIHmxbcPddmOQN0Fv+eA==,iv:SYCnFntCFE5mmk19p1kPyaAOZ6xzYbDOJcACzGyxY5E=,tag:xOjb9ApJ6OudbWGJe3serA==,type:str]
sops:
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age:
- recipient: age1clg0rd6ca86h3lnfnjyqsc9stgr0cnyp3l5uswtusxppjq9h2vcsaqckec
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBrWndEZ25hRHp1YXdSbXpr
TnpubDc4Q29qZ0lDdmU1QnJsRC9NYzRnY1ZZCkVHMmgySXpzLzJManZSdFF0VWoy
T0pGTlNpWmdYSG81SlRxc2tldzVOeHcKLS0tIGxJRTdFWGVzM3ExMnRpVnltaWxL
Tmc4dFlQc1FNaTdyeGNibytldTVROUkKMT4FyT6CfUSMJufIbShujfciU4zx+n76
5eZjbAuLZ/YZRUmkPuBn9qMjhcne6NbT3fn+3KNGEghUXne0M1UD8A==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2023-10-15T21:56:46Z"
mac: ENC[AES256_GCM,data:c/ajPjCiUIx/1Kf/9joyOv9XbX+TrnSUDs8j0PDNBubCBEaJNMxnav5LwGY17LH0HrvpQP64MPMZeXMpd6hIi+uH5/jv4xHR05ek4l8g6Fkcxn/vKQo3CYQQXFTASBOAYSwQaaR5PKdrUoNpyf2fBbHuJvyvfPRGJf8SdoTsZBc=,iv:qA/bFHENFVwOxL4cf3meGoT+sp0vyOl0AK9A6WHnrqg=,tag:auh4nts+ZS7Cx6RMWrJofA==,type:str]
pgp: []
encrypted_regex: ^(data|stringData)$
version: 3.8.0
7 changes: 7 additions & 0 deletions kubernetes/kube-nas/apps/cert-manager/kustomization.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
# yaml-language-server: $schema=https://json.schemastore.org/kustomization
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ./namespace.yaml
- ./cert-manager/flux-sync.yaml
8 changes: 8 additions & 0 deletions kubernetes/kube-nas/apps/cert-manager/namespace.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cert-manager
labels:
kustomize.toolkit.fluxcd.io/prune: disabled
goldilocks.fairwinds.com/enabled: "true"

0 comments on commit 0fcafae

Please sign in to comment.