1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
| apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: cert-d7z-net
namespace: cert-manager
spec:
secretTemplate:
annotations:
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "kube-system,default,core-system,core-middleware,core-app,share-app,monitor-app,dev-ops"
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "kube-system,default,core-system,core-middleware,core-app,share-app,monitor-app,dev-ops"
secretName: tls-pub-d7z
duration: 8760h # 1y
issuerRef:
name: self-issuer
commonName: "Self CA Certificate"
dnsNames:
- 'd7z.net'
- '*.d7z.net' # 通用公开地址
- '*.pages.d7z.net' # gitlab pages 相关地址
---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: cert-internal-d7z-net
namespace: cert-manager
spec:
secretTemplate:
annotations:
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "kube-system,default,core-system,core-middleware,core-app,share-app,monitor-app,dev-ops"
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "kube-system,default,core-system,core-middleware,core-app,share-app,monitor-app,dev-ops"
secretName: tls-pri-d7z
duration: 8760h # 1y
issuerRef:
name: self-issuer
commonName: "Self CA Certificate"
dnsNames:
- 'internal.d7z.net'
- '*.internal.d7z.net' # 通用私有地址
|