Question: Certificate or Annotations #3530
Unanswered
dustinmoris
asked this question in
Q&A
Replies: 1 comment
-
The ingress annotation creates a Certificate resources to save you time and give flexibility (read Helm charts).
|
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I just finished upgrading cert-manager from
v0.11.0
tov1.1.0
and ended up deleting everything from before and installing cert-manager from scratch.Our setup is AKS + NGINX ingress + cert-manager and previously I would have created a
Certificate
resource myself in a yaml file and then configured the Ingress to pick up the stored tls secret, but I struggled to get the same working on the new version and ended up using thecert-manager.io/cluster-issuer: "letsencrypt-prod"
annotation.Is this the recommended way now? I see that on the certificate resource I'd have more control with extra configurations like the renew period for example.
Couple other questions:
kubernetes.io/tls-acme: "true"
exactly mean/do?The official documentation is very thin on those topics, what the recommended way is to manage ACME certificates and what it means to use certain annotations and when one would like to use an annotation and when not.
Would be good to expand the documentation more, make it very explicit how cert-manager should ideally be configured and so on.
Beta Was this translation helpful? Give feedback.
All reactions