Add cert-manager Certificate for intranet ACME TLS auto-renewal

This commit is contained in:
Claude Code
2026-04-05 08:47:42 -05:00
parent 56442ecfbc
commit f3919cf728

View File

@@ -1,8 +1,6 @@
apiVersion: v1 apiVersion: v1
kind: Namespace kind: Namespace
metadata: metadata:
labels:
app.kubernetes.io/part-of: bluejay-infra
name: intranet name: intranet
--- ---
apiVersion: apps/v1 apiVersion: apps/v1
@@ -12,7 +10,6 @@ metadata:
namespace: intranet namespace: intranet
labels: labels:
app: intranet-web app: intranet-web
app.kubernetes.io/part-of: bluejay-infra
spec: spec:
replicas: 1 replicas: 1
selector: selector:
@@ -60,8 +57,6 @@ kind: Service
metadata: metadata:
name: intranet-web name: intranet-web
namespace: intranet namespace: intranet
labels:
app.kubernetes.io/part-of: bluejay-infra
spec: spec:
selector: selector:
app: intranet-web app: intranet-web
@@ -70,13 +65,24 @@ spec:
targetPort: 5300 targetPort: 5300
name: http name: http
--- ---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: intranet-tls
namespace: intranet
spec:
secretName: intranet-tls
issuerRef:
name: step-ca-acme
kind: ClusterIssuer
dnsNames:
- intranet.iamworkin.lan
---
apiVersion: traefik.io/v1alpha1 apiVersion: traefik.io/v1alpha1
kind: IngressRoute kind: IngressRoute
metadata: metadata:
name: intranet name: intranet
namespace: intranet namespace: intranet
labels:
app.kubernetes.io/part-of: bluejay-infra
spec: spec:
entryPoints: entryPoints:
- websecure - websecure
@@ -87,4 +93,4 @@ spec:
- name: intranet-web - name: intranet-web
port: 5300 port: 5300
tls: tls:
certResolver: step-ca secretName: intranet-tls