# Certificate for network.iamworkin.lan. # # Preflight gate: network.iamworkin.lan must resolve to 10.0.56.200 before this # Certificate is synced. step-ca ACME cannot see the CoreDNS wildcard # (*.iamworkin.lan -> 10.0.56.200) — it does an HTTP-01 challenge against the # resolved host. The CoreDNS wildcard template covers network.iamworkin.lan, so # resolution exists fleet-wide; do NOT add a pfSense DNS override (this plane is # read-only and holds no pfSense creds). If ACME backs off, confirm the wildcard # resolves first (feedback_pfsense_dns_required_for_acme). apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: fc-network-web-tls namespace: fc-network labels: app: fc-network-web app.kubernetes.io/name: fc-network-web app.kubernetes.io/component: web app.kubernetes.io/part-of: flowercore app.kubernetes.io/managed-by: argocd flowercore.io/tenant-id: system flowercore.io/created-by: bluejay-infra annotations: flowercore.io/dns-preflight: "network.iamworkin.lan must resolve to 10.0.56.200 (CoreDNS wildcard) before ACME sync" spec: secretName: fc-network-web-tls issuerRef: name: step-ca-acme kind: ClusterIssuer dnsNames: - network.iamworkin.lan duration: 720h renewBefore: 240h