I recently started deploying a k8s cluster in my home cluster, and I needed to setup an internal domain for my LAN, wherein I needed to get an ACME based ClusterIssuer.

Step CA provides a way to do it without ACME too, but I used ACME as that’s what I’d use for an actual final production deployment.


First things first

To avoid the pitfalls, and countless hours of stressing that I had to face, ensure you follow the networking setup steps for Kubernetes Cluster Setup.


Install k0s

In case you haven’t you can go through How I setup my bare metal Kubernetes Cluster with k0s.


Install Cert Manager

To be able to do this, you’ll need Cert Manager. In case you haven’t, you can go through How I setup my Custom domain Step-CA backed Cert Manager with my k0s Kubernetes cluster.


Setup the Cluster Issuer with my custom Step-CA ACME server

I’d already setup a Step-CA based ACME server on my controller plane node, which was also acting as the ca issuer. With k0s and the Cert Manager feature that we enabled to support it, I was able to setup the custom Step-CA ACME server to work with my cluster issuer.

apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
  name: letsencrypt-k0r0pt
spec:
  acme:
    # You must replace this email address with your own.
    # Let's Encrypt will use this to contact you about expiring
    # certificates, and issues related to your account.
    email: [email protected]
    server: https://ca.k0r0pt.int:50443/acme/k0r0pt-acme/directory
    caBundle: REDACTED
    privateKeySecretRef:
      # Secret resource that will be used to store the account's private key.
      name: k0r0pt-issuer-account-key
    # Add a single challenge solver, HTTP01 using nginx
    solvers:
      - http01:
          ingress:
            ingressClassName: nginx

Once I’d applied this with kubectl apply -f cert-manager-k0r0pt-issuer.yml, I verified that the ClusterIssuer was indeed setup - kubectl get clusterissuers.