2020-10-05 03:50:23 -07:00
|
|
|
# kubezero-cert-manager
|
|
|
|
|
2020-11-21 04:24:57 -08:00
|
|
|
 
|
2020-10-05 03:50:23 -07:00
|
|
|
|
2020-05-19 13:44:01 +01:00
|
|
|
KubeZero Umbrella Chart for cert-manager
|
|
|
|
|
2020-10-05 03:50:23 -07:00
|
|
|
**Homepage:** <https://kubezero.com>
|
|
|
|
|
|
|
|
## Maintainers
|
|
|
|
|
|
|
|
| Name | Email | Url |
|
|
|
|
| ---- | ------ | --- |
|
|
|
|
| Quarky9 | | |
|
2020-05-19 13:44:01 +01:00
|
|
|
|
2020-10-05 03:50:23 -07:00
|
|
|
## Requirements
|
2020-05-19 13:44:01 +01:00
|
|
|
|
2020-10-05 03:50:23 -07:00
|
|
|
Kubernetes: `>= 1.16.0`
|
2020-05-19 13:44:01 +01:00
|
|
|
|
|
|
|
| Repository | Name | Version |
|
|
|
|
|------------|------|---------|
|
2020-11-30 09:30:06 -08:00
|
|
|
| https://charts.jetstack.io | cert-manager | 1.1.0 |
|
2020-08-14 17:05:25 +01:00
|
|
|
| https://zero-down-time.github.io/kubezero/ | kubezero-lib | >= 0.1.3 |
|
2020-05-19 13:44:01 +01:00
|
|
|
|
2020-06-14 17:59:56 +01:00
|
|
|
## AWS - IAM Role
|
|
|
|
If you use kiam or kube2iam and restrict access on nodes running cert-manager please adjust:
|
|
|
|
```
|
|
|
|
cert-manager.podAnnotations:
|
|
|
|
iam.amazonaws.com/role: <ROLE>
|
|
|
|
```
|
|
|
|
|
|
|
|
## Resolver Secrets
|
|
|
|
If your resolvers need additional sercrets like CloudFlare API tokens etc. make sure to provide these secrets separatly matching your defined issuers.
|
|
|
|
|
2020-10-05 03:50:23 -07:00
|
|
|
## Values
|
2020-05-19 13:44:01 +01:00
|
|
|
|
|
|
|
| Key | Type | Default | Description |
|
|
|
|
|-----|------|---------|-------------|
|
|
|
|
| cert-manager.cainjector.nodeSelector."node-role.kubernetes.io/master" | string | `""` | |
|
|
|
|
| cert-manager.cainjector.tolerations[0].effect | string | `"NoSchedule"` | |
|
|
|
|
| cert-manager.cainjector.tolerations[0].key | string | `"node-role.kubernetes.io/master"` | |
|
2020-11-21 04:24:57 -08:00
|
|
|
| cert-manager.enabled | bool | `true` | |
|
2020-05-19 13:44:01 +01:00
|
|
|
| cert-manager.extraArgs[0] | string | `"--dns01-recursive-nameservers-only"` | |
|
2020-11-24 06:44:57 -08:00
|
|
|
| cert-manager.global.leaderElection.namespace | string | `"cert-manager"` | |
|
2020-05-19 13:44:01 +01:00
|
|
|
| cert-manager.ingressShim.defaultIssuerKind | string | `"ClusterIssuer"` | |
|
|
|
|
| cert-manager.ingressShim.defaultIssuerName | string | `"letsencrypt-dns-prod"` | |
|
|
|
|
| cert-manager.nodeSelector."node-role.kubernetes.io/master" | string | `""` | |
|
2020-11-24 06:44:57 -08:00
|
|
|
| cert-manager.podAnnotations | object | `{}` | |
|
2020-05-19 13:44:01 +01:00
|
|
|
| cert-manager.prometheus.servicemonitor.enabled | bool | `false` | |
|
|
|
|
| cert-manager.tolerations[0].effect | string | `"NoSchedule"` | |
|
|
|
|
| cert-manager.tolerations[0].key | string | `"node-role.kubernetes.io/master"` | |
|
|
|
|
| cert-manager.webhook.nodeSelector."node-role.kubernetes.io/master" | string | `""` | |
|
|
|
|
| cert-manager.webhook.tolerations[0].effect | string | `"NoSchedule"` | |
|
|
|
|
| cert-manager.webhook.tolerations[0].key | string | `"node-role.kubernetes.io/master"` | |
|
|
|
|
| clusterIssuer | object | `{}` | |
|
2020-11-21 04:24:57 -08:00
|
|
|
| localCA.enabled | bool | `false` | |
|
2020-05-19 13:44:01 +01:00
|
|
|
| localCA.selfsigning | bool | `true` | |
|