This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision | |||
|
система_kubernetes [2025/12/28 15:57] val [cert-manager] |
система_kubernetes [2025/12/28 16:04] (current) val [cert-manager] |
||
|---|---|---|---|
| Line 2504: | Line 2504: | ||
| student@vps:~$ kubectl -n cert-manager get all | student@vps:~$ kubectl -n cert-manager get all | ||
| + | |||
| + | student@vps:~$ #kubectl create secret generic cert-manager-tsig-secret --from-literal=tsig-secret-key="NNN...NNN" -n cert-manager | ||
| student@vps:~$ cat ...issuer.yaml | student@vps:~$ cat ...issuer.yaml | ||
| Line 2514: | Line 2516: | ||
| #name: letsencrypt-prod-clusterissuer | #name: letsencrypt-prod-clusterissuer | ||
| #name: freeipa-clusterissuer | #name: freeipa-clusterissuer | ||
| + | #name: freeipa-dns-clusterissuer | ||
| spec: | spec: | ||
| acme: | acme: | ||
| Line 2532: | Line 2535: | ||
| #- dns01: | #- dns01: | ||
| #rfc2136: | #rfc2136: | ||
| - | #nameserver: 172.19.32.2 | + | #nameserver: 192.168.X.10 |
| - | #tsigKeyName: certbot.anysite | + | #tsigKeyName: cert-manager |
| - | #tsigAlgorithm: HMACSHA512 | + | #tsigAlgorithm: HMACSHA256 |
| #tsigSecretSecretRef: | #tsigSecretSecretRef: | ||
| - | #name: anysite-tsig-secret | + | #name: cert-manager-tsig-secret |
| #key: tsig-secret-key | #key: tsig-secret-key | ||
| + | |||
| </code><code> | </code><code> | ||
| student@vps:~$ kubectl apply -f ...issuer.yaml #-n my-ns | student@vps:~$ kubectl apply -f ...issuer.yaml #-n my-ns | ||
| Line 2547: | Line 2551: | ||
| NAME READY AGE | NAME READY AGE | ||
| ...issuer True 42s | ...issuer True 42s | ||
| - | |||
| - | |||
| - | student@vps:~/pywebd-k8s$ kubectl -n my-pywebd-ns create secret generic anysite-tsig-secret --from-literal=tsig-secret-key="NNN...NNN" | ||
| </code> | </code> | ||