29 lines
896 B
YAML
29 lines
896 B
YAML
---
|
|
apiVersion: cert-manager.io/v1
|
|
kind: ClusterIssuer
|
|
metadata:
|
|
name: rfc2136-issuer
|
|
spec:
|
|
acme:
|
|
#server: https://acme-staging-v02.api.letsencrypt.org/directory
|
|
server: https://acme-v02.api.letsencrypt.org/directory
|
|
email: abuse@mziesel.com
|
|
|
|
# Name of a secret used to store the ACME account private key
|
|
privateKeySecretRef:
|
|
name: letsencrypt-staging-acme-key
|
|
|
|
# ACME DNS-01 provider configurations
|
|
solvers:
|
|
# An empty 'selector' means that this solver matches all domains
|
|
- selector: {}
|
|
dns01:
|
|
rfc2136:
|
|
# kubectl -n cert-manager create secret generic tsig-secret --from-literal=tsig-secret-key="[redacted]"
|
|
nameserver: "ns-master.as205079.net"
|
|
tsigKeyName: "cert-manager01"
|
|
tsigAlgorithm: HMACSHA512
|
|
tsigSecretSecretRef:
|
|
name: tsig-secret
|
|
key: tsig-secret-key
|