I recently started deploying a k8s cluster in my home cluster, and I needed to setup an internal domain for my LAN, wherein I needed to get an ACME based ClusterIssuer.
Step CA provides a way to do it without ACME too, but I used ACME as that’s what I’d use for an actual final production deployment.
First things first
To avoid the pitfalls, and countless hours of stressing that I had to face, ensure you follow the networking setup steps for Kubernetes Cluster Setup.
Install k0s
In case you haven’t you can go through How I setup my bare metal Kubernetes Cluster with k0s.
Install Cert Manager
To be able to do this, you’ll need Cert Manager. In case you haven’t, you can go through How I setup my Custom domain Step-CA backed Cert Manager with my k0s Kubernetes cluster.
Setup the Cluster Issuer with my custom Step-CA ACME server
I’d already setup a Step-CA based ACME server on my controller plane node, which was also acting as the ca issuer. With k0s and the Cert Manager feature that we enabled to support it, I was able to setup the custom Step-CA ACME server to work with my cluster issuer.
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt-k0r0pt
spec:
acme:
# You must replace this email address with your own.
# Let's Encrypt will use this to contact you about expiring
# certificates, and issues related to your account.
email: [email protected]
server: https://ca.k0r0pt.int:50443/acme/k0r0pt-acme/directory
caBundle: REDACTED
privateKeySecretRef:
# Secret resource that will be used to store the account's private key.
name: k0r0pt-issuer-account-key
# Add a single challenge solver, HTTP01 using nginx
solvers:
- http01:
ingress:
ingressClassName: nginxOnce I’d applied this with kubectl apply -f cert-manager-k0r0pt-issuer.yml, I verified that the ClusterIssuer was indeed setup - kubectl get clusterissuers.