Cert-Manager Integration
Setup
The following sections will guide you through the one-time setup that is required for providing certificates using cert-manager and kube-bind.
Follow the prerequisites, then select the provider:
Install cert-manager
Install cert-manager in your Kubernetes cluster, where kube-bind backend is running, if you haven't already. You can follow the official installation guide.
Export the Certificate CRD
To export the cert-manager Certificate CRD, add the kube-bind export label to it:
Create a SelfSigned Issuer
kubectl apply -f - <<EOF
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: my-selfsigned-issuer
spec:
selfSigned: {}
EOF
Create a Catalog Export
It's now time to configure kube-bind to export the certificate resource. Create a catalog Export for Certificate resources like this one:
kubectl apply -f - <<EOF
apiVersion: catalog.kbind.io/v1alpha1
kind: Export
metadata:
name: certificate
spec:
title: Certificate
description: Manage TLS certificates with cert-manager.
apis:
- name: certificates.cert-manager.io
defaults:
relatedResources:
- group: ""
resource: secrets
direction: FromProvider
selector:
names:
- my-tls-cert
EOF
This walkthrough keeps the original fixed my-tls-cert Secret name. v2 related-resource selectors are name/label based, they do not follow spec.secretName. If you change the Secret name, update the Export selector to match.
Usage
Now that everything is set up, users can begin to bind to your backend and begin consuming the new API.
Login to kube-bind
Bind the Export
The command applies the bundle for the certificate Export to the consumer cluster. It assumes a matching konnector is already installed separately.
Create a Certificate
Now you can finally create a Certificate object in your consumer cluster. The cert-manager in the provider cluster will handle the issuance and management of the TLS certificate.
Note
my-selfsigned-issuer must be present in the provider cluster for this example to work.
kubectl apply -f - <<EOF
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: my-tls-cert
namespace: default
spec:
commonName: my-ca
isCA: true
issuerRef:
kind: ClusterIssuer
name: my-selfsigned-issuer
secretName: my-tls-cert
EOF
Wait for Provisioning
Observe that the Certificate object is created in the consumer cluster and the corresponding TLS Secret is generated and copied through the related-resource rule: