-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathcertManager.ts
More file actions
67 lines (64 loc) · 1.77 KB
/
Copy pathcertManager.ts
File metadata and controls
67 lines (64 loc) · 1.77 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
import * as pulumi from "@pulumi/pulumi";
import * as k8s from "@pulumi/kubernetes";
import { doK8sProvider } from "./cluster";
import { config } from "./index";
// Cert-Manager Helm chart
export const certManagerNamespace = new k8s.core.v1.Namespace("cert-manager", {
metadata: { name: "cert-manager" },
}, { provider: doK8sProvider });
export const certManagerChart = new k8s.helm.v3.Release("cert-manager", {
chart: "cert-manager",
namespace: certManagerNamespace.metadata.name,
repositoryOpts: {
repo: "https://charts.jetstack.io",
},
values: {
installCRDs: true,
livenessProbe: {
enabled: true,
},
},
version: "1.12.1", // Cert-Manager Helm chart version
}, { provider: doK8sProvider });
// Create a ClusterIssuer for Let's Encrypt
export const letsEncryptClusterIssuer = new k8s.apiextensions.CustomResource(
"letsencrypt",
{
apiVersion: "cert-manager.io/v1",
kind: "ClusterIssuer",
metadata: { name: "letsencrypt" },
spec: {
acme: {
server: "https://acme-v02.api.letsencrypt.org/directory",
email: "admin@adb.sh",
privateKeySecretRef: {
name: "letsencrypt-account-key",
},
solvers: [
{
selector: {
dnsZones: [config.require("knative-domain")],
},
dns01: {
digitalocean: {
tokenSecretRef: {
name: "lets-encrypt-do-dns",
key: "access-token",
},
},
},
},
{
selector: {},
http01: {
ingress: {
class: "traefik",
},
},
},
],
},
},
},
{ dependsOn: certManagerChart, provider: doK8sProvider },
);