@@ -19,7 +19,7 @@ metadata:
19
19
name : knative-serving-certmanager
20
20
labels :
21
21
app.kubernetes.io/component : net-certmanager
22
- app.kubernetes.io/version : " 20231130-a1f69511 "
22
+ app.kubernetes.io/version : " 20231130-95439a33 "
23
23
app.kubernetes.io/name : knative-serving
24
24
serving.knative.dev/controller : " true"
25
25
networking.knative.dev/certificate-provider : cert-manager
@@ -52,7 +52,7 @@ metadata:
52
52
name : config.webhook.net-certmanager.networking.internal.knative.dev
53
53
labels :
54
54
app.kubernetes.io/component : net-certmanager
55
- app.kubernetes.io/version : " 20231130-a1f69511 "
55
+ app.kubernetes.io/version : " 20231130-95439a33 "
56
56
app.kubernetes.io/name : knative-serving
57
57
networking.knative.dev/certificate-provider : cert-manager
58
58
webhooks :
@@ -93,7 +93,7 @@ metadata:
93
93
namespace : knative-serving
94
94
labels :
95
95
app.kubernetes.io/component : net-certmanager
96
- app.kubernetes.io/version : " 20231130-a1f69511 "
96
+ app.kubernetes.io/version : " 20231130-95439a33 "
97
97
app.kubernetes.io/name : knative-serving
98
98
networking.knative.dev/certificate-provider : cert-manager
99
99
@@ -119,7 +119,7 @@ metadata:
119
119
namespace : knative-serving
120
120
labels :
121
121
app.kubernetes.io/component : net-certmanager
122
- app.kubernetes.io/version : " 20231130-a1f69511 "
122
+ app.kubernetes.io/version : " 20231130-95439a33 "
123
123
app.kubernetes.io/name : knative-serving
124
124
networking.knative.dev/certificate-provider : cert-manager
125
125
data :
@@ -138,23 +138,32 @@ data:
138
138
# These sample configuration options may be copied out of
139
139
# this block and unindented to actually change the configuration.
140
140
141
- # issuerRef is a reference to the issuer for cluster external certificates used for ingress.
141
+ # issuerRef is a reference to the issuer for external-domain certificates used for ingress.
142
142
# IssuerRef should be either `ClusterIssuer` or `Issuer`.
143
143
# Please refer `IssuerRef` in https://github.com/cert-manager/cert-manager/tree/master/pkg/apis/certmanager/v1/types_certificate.go
144
144
# for more details about IssuerRef configuration.
145
- # If the issuerRef is not specified, the self-signed `knative-internal-encryption-ca ` ClusterIssuer is used.
145
+ # If the issuerRef is not specified, the self-signed `knative-selfsigned-issuer ` ClusterIssuer is used.
146
146
issuerRef: |
147
147
kind: ClusterIssuer
148
148
name: letsencrypt-issuer
149
149
150
- # clusterInternalIssuerRef is a reference to the issuer for cluster internal certificates used for ingress.
151
- # ClusterInternalIssuerRef should be either `ClusterIssuer` or `Issuer`.
150
+ # clusterLocalIssuerRef is a reference to the issuer for cluster-local-domain certificates used for ingress.
151
+ # clusterLocalIssuerRef should be either `ClusterIssuer` or `Issuer`.
152
152
# Please refer `IssuerRef` in https://github.com/cert-manager/cert-manager/tree/master/pkg/apis/certmanager/v1/types_certificate.go
153
153
# for more details about ClusterInternalIssuerRef configuration.
154
- # If the clusterInternalIssuerRef is not specified, the self-signed `knative-internal-encryption-ca ` ClusterIssuer is used.
155
- clusterInternalIssuerRef : |
154
+ # If the clusterLocalIssuerRef is not specified, the self-signed `knative-selfsigned-issuer ` ClusterIssuer is used.
155
+ clusterLocalIssuerRef : |
156
156
kind: ClusterIssuer
157
- name: knative-internal-encryption-issuer
157
+ name: your-company-issuer
158
+
159
+ # systemInternalIssuerRef is a reference to the issuer for certificates for system-internal-tls certificates used by Knative internal components.
160
+ # systemInternalIssuerRef should be either `ClusterIssuer` or `Issuer`.
161
+ # Please refer `IssuerRef` in https://github.com/cert-manager/cert-manager/tree/master/pkg/apis/certmanager/v1/types_certificate.go
162
+ # for more details about ClusterInternalIssuerRef configuration.
163
+ # If the systemInternalIssuerRef is not specified, the self-signed `knative-selfsigned-issuer` ClusterIssuer is used.
164
+ systemInternalIssuerRef: |
165
+ kind: ClusterIssuer
166
+ name: knative-selfsigned-issuer
158
167
159
168
---
160
169
# Copyright 2020 The Knative Authors
@@ -178,7 +187,7 @@ metadata:
178
187
namespace : knative-serving
179
188
labels :
180
189
app.kubernetes.io/component : net-certmanager
181
- app.kubernetes.io/version : " 20231130-a1f69511 "
190
+ app.kubernetes.io/version : " 20231130-95439a33 "
182
191
app.kubernetes.io/name : knative-serving
183
192
networking.knative.dev/certificate-provider : cert-manager
184
193
spec :
@@ -190,15 +199,15 @@ spec:
190
199
labels :
191
200
app : net-certmanager-controller
192
201
app.kubernetes.io/component : net-certmanager
193
- app.kubernetes.io/version : " 20231130-a1f69511 "
202
+ app.kubernetes.io/version : " 20231130-95439a33 "
194
203
app.kubernetes.io/name : knative-serving
195
204
spec :
196
205
serviceAccountName : controller
197
206
containers :
198
207
- name : controller
199
208
# This is the Go import path for the binary that is containerized
200
209
# and substituted here.
201
- image : gcr .io/knative-nightly/knative.dev/ net-certmanager/cmd/ controller@sha256:303e0dd098e5e61074e1114f13944a0c9b287686e964abafc68c18be025fca7f
210
+ image : quay .io/rlehmann/ net-certmanager- controller
202
211
resources :
203
212
requests :
204
213
cpu : 30m
@@ -239,7 +248,7 @@ metadata:
239
248
labels :
240
249
app : net-certmanager-controller
241
250
app.kubernetes.io/component : net-certmanager
242
- app.kubernetes.io/version : " 20231130-a1f69511 "
251
+ app.kubernetes.io/version : " 20231130-95439a33 "
243
252
app.kubernetes.io/name : knative-serving
244
253
networking.knative.dev/certificate-provider : cert-manager
245
254
name : net-certmanager-controller
@@ -277,37 +286,40 @@ metadata:
277
286
name : selfsigned-cluster-issuer
278
287
labels :
279
288
app.kubernetes.io/component : net-certmanager
280
- app.kubernetes.io/version : " 20231130-a1f69511 "
289
+ app.kubernetes.io/version : " 20231130-95439a33 "
281
290
app.kubernetes.io/name : knative-serving
282
291
networking.knative.dev/certificate-provider : cert-manager
292
+ knative.dev/issuer-install : " true"
283
293
spec :
284
294
selfSigned : {}
285
295
---
286
296
apiVersion : cert-manager.io/v1
287
297
kind : ClusterIssuer
288
298
metadata :
289
- name : knative-internal-encryption -issuer
299
+ name : knative-selfsigned -issuer
290
300
labels :
291
301
app.kubernetes.io/component : net-certmanager
292
- app.kubernetes.io/version : " 20231130-a1f69511 "
302
+ app.kubernetes.io/version : " 20231130-95439a33 "
293
303
app.kubernetes.io/name : knative-serving
294
304
networking.knative.dev/certificate-provider : cert-manager
305
+ knative.dev/issuer-install : " true"
295
306
spec :
296
307
ca :
297
- secretName : knative-internal-encryption -ca
308
+ secretName : knative-selfsigned -ca
298
309
---
299
310
apiVersion : cert-manager.io/v1
300
311
kind : Certificate
301
312
metadata :
302
- name : knative-internal-encryption -ca
313
+ name : knative-selfsigned -ca
303
314
namespace : cert-manager # If you want to use it as a ClusterIssuer the secret must be in the cert-manager namespace.
304
315
labels :
305
316
app.kubernetes.io/component : net-certmanager
306
- app.kubernetes.io/version : " 20231130-a1f69511 "
317
+ app.kubernetes.io/version : " 20231130-95439a33 "
307
318
app.kubernetes.io/name : knative-serving
308
319
networking.knative.dev/certificate-provider : cert-manager
320
+ knative.dev/issuer-install : " true"
309
321
spec :
310
- secretName : knative-internal-encryption -ca
322
+ secretName : knative-selfsigned -ca
311
323
commonName : knative.dev
312
324
usages :
313
325
- server auth
@@ -338,7 +350,7 @@ metadata:
338
350
namespace : knative-serving
339
351
labels :
340
352
app.kubernetes.io/component : net-certmanager
341
- app.kubernetes.io/version : " 20231130-a1f69511 "
353
+ app.kubernetes.io/version : " 20231130-95439a33 "
342
354
app.kubernetes.io/name : knative-serving
343
355
networking.knative.dev/certificate-provider : cert-manager
344
356
spec :
@@ -351,7 +363,7 @@ spec:
351
363
labels :
352
364
app : net-certmanager-webhook
353
365
app.kubernetes.io/component : net-certmanager
354
- app.kubernetes.io/version : " 20231130-a1f69511 "
366
+ app.kubernetes.io/version : " 20231130-95439a33 "
355
367
app.kubernetes.io/name : knative-serving
356
368
role : net-certmanager-webhook
357
369
spec :
@@ -360,7 +372,7 @@ spec:
360
372
- name : webhook
361
373
# This is the Go import path for the binary that is containerized
362
374
# and substituted here.
363
- image : gcr .io/knative-nightly/knative.dev/ net-certmanager/cmd/ webhook@sha256:dbad94db119ee80aabe5ddf6d9a97e4c699d26d72dfed01d9937fcdaa849fa3a
375
+ image : quay .io/rlehmann/ net-certmanager- webhook
364
376
resources :
365
377
requests :
366
378
cpu : 20m
@@ -426,7 +438,7 @@ metadata:
426
438
labels :
427
439
role : net-certmanager-webhook
428
440
app.kubernetes.io/component : net-certmanager
429
- app.kubernetes.io/version : " 20231130-a1f69511 "
441
+ app.kubernetes.io/version : " 20231130-95439a33 "
430
442
app.kubernetes.io/name : knative-serving
431
443
networking.knative.dev/certificate-provider : cert-manager
432
444
spec :
0 commit comments