Skip to content

Commit 8ad22bc

Browse files
committed
TEMPORARY: use unmerged versions of net-kourier + net-cert-manager
1 parent f1ba4ee commit 8ad22bc

File tree

2 files changed

+56
-44
lines changed

2 files changed

+56
-44
lines changed

third_party/cert-manager-latest/net-certmanager.yaml

Lines changed: 38 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ metadata:
1919
name: knative-serving-certmanager
2020
labels:
2121
app.kubernetes.io/component: net-certmanager
22-
app.kubernetes.io/version: "20231130-a1f69511"
22+
app.kubernetes.io/version: "20231130-95439a33"
2323
app.kubernetes.io/name: knative-serving
2424
serving.knative.dev/controller: "true"
2525
networking.knative.dev/certificate-provider: cert-manager
@@ -52,7 +52,7 @@ metadata:
5252
name: config.webhook.net-certmanager.networking.internal.knative.dev
5353
labels:
5454
app.kubernetes.io/component: net-certmanager
55-
app.kubernetes.io/version: "20231130-a1f69511"
55+
app.kubernetes.io/version: "20231130-95439a33"
5656
app.kubernetes.io/name: knative-serving
5757
networking.knative.dev/certificate-provider: cert-manager
5858
webhooks:
@@ -93,7 +93,7 @@ metadata:
9393
namespace: knative-serving
9494
labels:
9595
app.kubernetes.io/component: net-certmanager
96-
app.kubernetes.io/version: "20231130-a1f69511"
96+
app.kubernetes.io/version: "20231130-95439a33"
9797
app.kubernetes.io/name: knative-serving
9898
networking.knative.dev/certificate-provider: cert-manager
9999

@@ -119,7 +119,7 @@ metadata:
119119
namespace: knative-serving
120120
labels:
121121
app.kubernetes.io/component: net-certmanager
122-
app.kubernetes.io/version: "20231130-a1f69511"
122+
app.kubernetes.io/version: "20231130-95439a33"
123123
app.kubernetes.io/name: knative-serving
124124
networking.knative.dev/certificate-provider: cert-manager
125125
data:
@@ -138,23 +138,32 @@ data:
138138
# These sample configuration options may be copied out of
139139
# this block and unindented to actually change the configuration.
140140
141-
# issuerRef is a reference to the issuer for cluster external certificates used for ingress.
141+
# issuerRef is a reference to the issuer for external-domain certificates used for ingress.
142142
# IssuerRef should be either `ClusterIssuer` or `Issuer`.
143143
# Please refer `IssuerRef` in https://github.com/cert-manager/cert-manager/tree/master/pkg/apis/certmanager/v1/types_certificate.go
144144
# for more details about IssuerRef configuration.
145-
# If the issuerRef is not specified, the self-signed `knative-internal-encryption-ca` ClusterIssuer is used.
145+
# If the issuerRef is not specified, the self-signed `knative-selfsigned-issuer` ClusterIssuer is used.
146146
issuerRef: |
147147
kind: ClusterIssuer
148148
name: letsencrypt-issuer
149149
150-
# clusterInternalIssuerRef is a reference to the issuer for cluster internal certificates used for ingress.
151-
# ClusterInternalIssuerRef should be either `ClusterIssuer` or `Issuer`.
150+
# clusterLocalIssuerRef is a reference to the issuer for cluster-local-domain certificates used for ingress.
151+
# clusterLocalIssuerRef should be either `ClusterIssuer` or `Issuer`.
152152
# Please refer `IssuerRef` in https://github.com/cert-manager/cert-manager/tree/master/pkg/apis/certmanager/v1/types_certificate.go
153153
# for more details about ClusterInternalIssuerRef configuration.
154-
# If the clusterInternalIssuerRef is not specified, the self-signed `knative-internal-encryption-ca` ClusterIssuer is used.
155-
clusterInternalIssuerRef: |
154+
# If the clusterLocalIssuerRef is not specified, the self-signed `knative-selfsigned-issuer` ClusterIssuer is used.
155+
clusterLocalIssuerRef: |
156156
kind: ClusterIssuer
157-
name: knative-internal-encryption-issuer
157+
name: your-company-issuer
158+
159+
# systemInternalIssuerRef is a reference to the issuer for certificates for system-internal-tls certificates used by Knative internal components.
160+
# systemInternalIssuerRef should be either `ClusterIssuer` or `Issuer`.
161+
# Please refer `IssuerRef` in https://github.com/cert-manager/cert-manager/tree/master/pkg/apis/certmanager/v1/types_certificate.go
162+
# for more details about ClusterInternalIssuerRef configuration.
163+
# If the systemInternalIssuerRef is not specified, the self-signed `knative-selfsigned-issuer` ClusterIssuer is used.
164+
systemInternalIssuerRef: |
165+
kind: ClusterIssuer
166+
name: knative-selfsigned-issuer
158167
159168
---
160169
# Copyright 2020 The Knative Authors
@@ -178,7 +187,7 @@ metadata:
178187
namespace: knative-serving
179188
labels:
180189
app.kubernetes.io/component: net-certmanager
181-
app.kubernetes.io/version: "20231130-a1f69511"
190+
app.kubernetes.io/version: "20231130-95439a33"
182191
app.kubernetes.io/name: knative-serving
183192
networking.knative.dev/certificate-provider: cert-manager
184193
spec:
@@ -190,15 +199,15 @@ spec:
190199
labels:
191200
app: net-certmanager-controller
192201
app.kubernetes.io/component: net-certmanager
193-
app.kubernetes.io/version: "20231130-a1f69511"
202+
app.kubernetes.io/version: "20231130-95439a33"
194203
app.kubernetes.io/name: knative-serving
195204
spec:
196205
serviceAccountName: controller
197206
containers:
198207
- name: controller
199208
# This is the Go import path for the binary that is containerized
200209
# and substituted here.
201-
image: gcr.io/knative-nightly/knative.dev/net-certmanager/cmd/controller@sha256:303e0dd098e5e61074e1114f13944a0c9b287686e964abafc68c18be025fca7f
210+
image: quay.io/rlehmann/net-certmanager-controller
202211
resources:
203212
requests:
204213
cpu: 30m
@@ -239,7 +248,7 @@ metadata:
239248
labels:
240249
app: net-certmanager-controller
241250
app.kubernetes.io/component: net-certmanager
242-
app.kubernetes.io/version: "20231130-a1f69511"
251+
app.kubernetes.io/version: "20231130-95439a33"
243252
app.kubernetes.io/name: knative-serving
244253
networking.knative.dev/certificate-provider: cert-manager
245254
name: net-certmanager-controller
@@ -277,37 +286,40 @@ metadata:
277286
name: selfsigned-cluster-issuer
278287
labels:
279288
app.kubernetes.io/component: net-certmanager
280-
app.kubernetes.io/version: "20231130-a1f69511"
289+
app.kubernetes.io/version: "20231130-95439a33"
281290
app.kubernetes.io/name: knative-serving
282291
networking.knative.dev/certificate-provider: cert-manager
292+
knative.dev/issuer-install: "true"
283293
spec:
284294
selfSigned: {}
285295
---
286296
apiVersion: cert-manager.io/v1
287297
kind: ClusterIssuer
288298
metadata:
289-
name: knative-internal-encryption-issuer
299+
name: knative-selfsigned-issuer
290300
labels:
291301
app.kubernetes.io/component: net-certmanager
292-
app.kubernetes.io/version: "20231130-a1f69511"
302+
app.kubernetes.io/version: "20231130-95439a33"
293303
app.kubernetes.io/name: knative-serving
294304
networking.knative.dev/certificate-provider: cert-manager
305+
knative.dev/issuer-install: "true"
295306
spec:
296307
ca:
297-
secretName: knative-internal-encryption-ca
308+
secretName: knative-selfsigned-ca
298309
---
299310
apiVersion: cert-manager.io/v1
300311
kind: Certificate
301312
metadata:
302-
name: knative-internal-encryption-ca
313+
name: knative-selfsigned-ca
303314
namespace: cert-manager # If you want to use it as a ClusterIssuer the secret must be in the cert-manager namespace.
304315
labels:
305316
app.kubernetes.io/component: net-certmanager
306-
app.kubernetes.io/version: "20231130-a1f69511"
317+
app.kubernetes.io/version: "20231130-95439a33"
307318
app.kubernetes.io/name: knative-serving
308319
networking.knative.dev/certificate-provider: cert-manager
320+
knative.dev/issuer-install: "true"
309321
spec:
310-
secretName: knative-internal-encryption-ca
322+
secretName: knative-selfsigned-ca
311323
commonName: knative.dev
312324
usages:
313325
- server auth
@@ -338,7 +350,7 @@ metadata:
338350
namespace: knative-serving
339351
labels:
340352
app.kubernetes.io/component: net-certmanager
341-
app.kubernetes.io/version: "20231130-a1f69511"
353+
app.kubernetes.io/version: "20231130-95439a33"
342354
app.kubernetes.io/name: knative-serving
343355
networking.knative.dev/certificate-provider: cert-manager
344356
spec:
@@ -351,7 +363,7 @@ spec:
351363
labels:
352364
app: net-certmanager-webhook
353365
app.kubernetes.io/component: net-certmanager
354-
app.kubernetes.io/version: "20231130-a1f69511"
366+
app.kubernetes.io/version: "20231130-95439a33"
355367
app.kubernetes.io/name: knative-serving
356368
role: net-certmanager-webhook
357369
spec:
@@ -360,7 +372,7 @@ spec:
360372
- name: webhook
361373
# This is the Go import path for the binary that is containerized
362374
# and substituted here.
363-
image: gcr.io/knative-nightly/knative.dev/net-certmanager/cmd/webhook@sha256:dbad94db119ee80aabe5ddf6d9a97e4c699d26d72dfed01d9937fcdaa849fa3a
375+
image: quay.io/rlehmann/net-certmanager-webhook
364376
resources:
365377
requests:
366378
cpu: 20m
@@ -426,7 +438,7 @@ metadata:
426438
labels:
427439
role: net-certmanager-webhook
428440
app.kubernetes.io/component: net-certmanager
429-
app.kubernetes.io/version: "20231130-a1f69511"
441+
app.kubernetes.io/version: "20231130-95439a33"
430442
app.kubernetes.io/name: knative-serving
431443
networking.knative.dev/certificate-provider: cert-manager
432444
spec:

third_party/kourier-latest/kourier.yaml

Lines changed: 18 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ metadata:
2020
networking.knative.dev/ingress-provider: kourier
2121
app.kubernetes.io/name: knative-serving
2222
app.kubernetes.io/component: net-kourier
23-
app.kubernetes.io/version: "20231129-f286cd0d"
23+
app.kubernetes.io/version: "20231130-9f3405e7"
2424

2525
---
2626
# Copyright 2020 The Knative Authors
@@ -45,7 +45,7 @@ metadata:
4545
labels:
4646
networking.knative.dev/ingress-provider: kourier
4747
app.kubernetes.io/component: net-kourier
48-
app.kubernetes.io/version: "20231129-f286cd0d"
48+
app.kubernetes.io/version: "20231130-9f3405e7"
4949
app.kubernetes.io/name: knative-serving
5050
data:
5151
envoy-bootstrap.yaml: |
@@ -55,7 +55,7 @@ data:
5555
api_type: GRPC
5656
rate_limit_settings: {}
5757
grpc_services:
58-
- envoy_grpc: {cluster_name: xds_cluster}
58+
- envoy_grpc: {cluster_name: xds_cluster}
5959
cds_config:
6060
resource_api_version: V3
6161
ads: {}
@@ -133,9 +133,9 @@ data:
133133
type: STRICT_DNS
134134
admin:
135135
access_log:
136-
- name: envoy.access_loggers.stdout
137-
typed_config:
138-
"@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog
136+
- name: envoy.access_loggers.stdout
137+
typed_config:
138+
"@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog
139139
address:
140140
pipe:
141141
path: /tmp/envoy.admin
@@ -168,7 +168,7 @@ metadata:
168168
labels:
169169
networking.knative.dev/ingress-provider: kourier
170170
app.kubernetes.io/component: net-kourier
171-
app.kubernetes.io/version: "20231129-f286cd0d"
171+
app.kubernetes.io/version: "20231130-9f3405e7"
172172
app.kubernetes.io/name: knative-serving
173173
data:
174174
_example: |
@@ -248,7 +248,7 @@ metadata:
248248
labels:
249249
networking.knative.dev/ingress-provider: kourier
250250
app.kubernetes.io/component: net-kourier
251-
app.kubernetes.io/version: "20231129-f286cd0d"
251+
app.kubernetes.io/version: "20231130-9f3405e7"
252252
app.kubernetes.io/name: knative-serving
253253
---
254254
apiVersion: rbac.authorization.k8s.io/v1
@@ -258,7 +258,7 @@ metadata:
258258
labels:
259259
networking.knative.dev/ingress-provider: kourier
260260
app.kubernetes.io/component: net-kourier
261-
app.kubernetes.io/version: "20231129-f286cd0d"
261+
app.kubernetes.io/version: "20231130-9f3405e7"
262262
app.kubernetes.io/name: knative-serving
263263
rules:
264264
- apiGroups: [""]
@@ -287,7 +287,7 @@ metadata:
287287
labels:
288288
networking.knative.dev/ingress-provider: kourier
289289
app.kubernetes.io/component: net-kourier
290-
app.kubernetes.io/version: "20231129-f286cd0d"
290+
app.kubernetes.io/version: "20231130-9f3405e7"
291291
app.kubernetes.io/name: knative-serving
292292
roleRef:
293293
apiGroup: rbac.authorization.k8s.io
@@ -321,7 +321,7 @@ metadata:
321321
labels:
322322
networking.knative.dev/ingress-provider: kourier
323323
app.kubernetes.io/component: net-kourier
324-
app.kubernetes.io/version: "20231129-f286cd0d"
324+
app.kubernetes.io/version: "20231130-9f3405e7"
325325
app.kubernetes.io/name: knative-serving
326326
spec:
327327
strategy:
@@ -343,7 +343,7 @@ spec:
343343
app: net-kourier-controller
344344
spec:
345345
containers:
346-
- image: gcr.io/knative-nightly/knative.dev/net-kourier/cmd/kourier@sha256:735d111ef3b90e45b318017391737331b6065db9f2be88a0d91561e2d9b3df4d
346+
- image: quay.io/rlehmann/net-kourier
347347
name: controller
348348
env:
349349
- name: CERTS_SECRET_NAMESPACE
@@ -408,7 +408,7 @@ metadata:
408408
labels:
409409
networking.knative.dev/ingress-provider: kourier
410410
app.kubernetes.io/component: net-kourier
411-
app.kubernetes.io/version: "20231129-f286cd0d"
411+
app.kubernetes.io/version: "20231130-9f3405e7"
412412
app.kubernetes.io/name: knative-serving
413413
spec:
414414
ports:
@@ -443,7 +443,7 @@ metadata:
443443
labels:
444444
networking.knative.dev/ingress-provider: kourier
445445
app.kubernetes.io/component: net-kourier
446-
app.kubernetes.io/version: "20231129-f286cd0d"
446+
app.kubernetes.io/version: "20231130-9f3405e7"
447447
app.kubernetes.io/name: knative-serving
448448
spec:
449449
strategy:
@@ -552,7 +552,7 @@ metadata:
552552
labels:
553553
networking.knative.dev/ingress-provider: kourier
554554
app.kubernetes.io/component: net-kourier
555-
app.kubernetes.io/version: "20231129-f286cd0d"
555+
app.kubernetes.io/version: "20231130-9f3405e7"
556556
app.kubernetes.io/name: knative-serving
557557
spec:
558558
ports:
@@ -576,7 +576,7 @@ metadata:
576576
labels:
577577
networking.knative.dev/ingress-provider: kourier
578578
app.kubernetes.io/component: net-kourier
579-
app.kubernetes.io/version: "20231129-f286cd0d"
579+
app.kubernetes.io/version: "20231130-9f3405e7"
580580
app.kubernetes.io/name: knative-serving
581581
spec:
582582
ports:
@@ -600,7 +600,7 @@ metadata:
600600
labels:
601601
networking.knative.dev/ingress-provider: kourier
602602
app.kubernetes.io/component: net-kourier
603-
app.kubernetes.io/version: "20231129-f286cd0d"
603+
app.kubernetes.io/version: "20231130-9f3405e7"
604604
app.kubernetes.io/name: knative-serving
605605
spec:
606606
minReplicas: 1
@@ -626,7 +626,7 @@ metadata:
626626
labels:
627627
networking.knative.dev/ingress-provider: kourier
628628
app.kubernetes.io/component: net-kourier
629-
app.kubernetes.io/version: "20231129-f286cd0d"
629+
app.kubernetes.io/version: "20231130-9f3405e7"
630630
app.kubernetes.io/name: knative-serving
631631
spec:
632632
minAvailable: 80%

0 commit comments

Comments
 (0)