I am one step closer from changing my standalone self-hosted services to a k3s cluster.
I have another VPS where I (painfully) installed #openSUSE Tumbleweed and installed #k3s
Spent the entire afternoon trying to figure out #caddy ingress controller and #certmanager
Now I just need to find #helm charts for the services I want to host!
#opensuse #k3s #caddy #certmanager #helm
Is anyone savvy on #Kubernetes #Nginx and #CertManager that can help me get my cert-manager to work through the proxy-protocol? My cert-manager can't renew certificates with the proxy. And I need the proxy on so I can see IP addresses outside the server.
#kubernetes #nginx #certmanager
So far it seems to be a spec for how to define and then use standard naming (and naturally tokens/certs) to identify and then of course authenticate workloads #KubeCon
Best of all, a quick Google shows that there are already people playing with #SPIFFE and #OpenPolicyAgent
https://github.com/spiffe/spire-tutorials/blob/main/k8s/envoy-opa/k8s/backend/config/opa-policy.rego
This session is showing off integration with #CertManager
#kubecon #SPIFFE #OpenPolicyAgent #certmanager
How to Use #certmanager and #HashiCorp Vault to Manage #Certificates? https://api7.ai/blog/how-to-use-cert-manager-and-vault-to-manage-certifications
#certmanager #hashicorp #certificates
A Simple CA Setup with #Kubernetes #CertManager https://medium.com/geekculture/a-simple-ca-setup-with-kubernetes-cert-manager-bc8ccbd9c2
#Ansible and #Kubernetes was the topic today. I cover using #AWX with some playbooks to respin on-prem #k3s multi-node cluster without #traefik. We will create #Istio and #CertManager playbooks then tackle using #AzureDNS in a new #ClusterIssuer. See the video at the end of a full end-to-end demo. https://freshbrewed.science/2023/02/24/k3s-ansible-azuredns.html
#clusterissuer #azuredns #certmanager #istio #traefik #k3s #AWX #kubernetes #ansible
🖥️ #CertManager-Addon enabled... 💪
die #Zertifikate wollen aber trotzdem nicht, da ist noch etwas anderes im Argen 😫
#selfhosting #K8sathome #homelab #MicroK8s #k8s #cluster #BareMetal
#certmanager #Zertifikate #selfhosting #K8sathome #homelab #MicroK8s #k8s #cluster #BareMetal
🖥️ Gerade mein #Kubernetes-Cluster auf das aktuelle MicroK8s 1.26 stable upgedatet...
Mal sehen ob ich das mit den Zertifikaten mit dem neuen #CertManager-Addon zum laufen bekomme...
#selfhosting #K8sathome #homelab #MicroK8s #k8s #cluster #BareMetal
#kubernetes #certmanager #selfhosting #K8sathome #homelab #MicroK8s #k8s #cluster #BareMetal
What Is #HTTPS? How Does It Work? Automate With #certmanager And #LetsEncrypt https://www.youtube.com/watch?v=D7ijCjE31GA
#https #certmanager #letsencrypt #kubernetes
cert-manager automatically provisions and manage TLS certificates in Kubernetes.
https://github.com/cert-manager/cert-manager
#CertManager #certificate #Kubernetes #infra #tools #automation #renewal #TLS
#certmanager #certificate #kubernetes #infra #tools #automation #renewal #tls
hmm, so pinniped doesn't support the supervisor using a cert-manager generated certificate and NGINX doesn't like the Elliptic Curve cert auto generated by the supervisor. There's a Secret that gets generated, but it's not a standard #kubernetes TLS Secret (why???) so you can't use #certmanager to generate that cert. Guess I'll be deploying contour for this part of the #authentication deep dive.
#kubernetes #certmanager #authentication
🖥️ Mal wieder eine #Kubernetes-Frage:
Wie kann ich bei der #Helm-Installation von #certmanager
|annotations:
| kubernetes.io/ingress.class: "nginx"
in
|spec:
| ingressClassName: nginx
ändern?
Leider funktioniert die alte #Annotation in meiner #microK8s-Version 1.24 nicht mehr...
🔁 #Follwerpower gerne #Retoot #Boost
#kubernetes #helm #certmanager #annotation #MicroK8s #follwerpower #retoot #boost #K8sathome #homelab #k8s #cluster
Die letzten Tage konnte ich Erfolge mit meinem #Kubernetes-#Cluster verbuchen... 💪
Folgende #Dienste konnte ich via #Ansible #deploy|en:
#LogitechMediaServer
#PiHole
#UnifiController
#Jellyfin > will nur noch nicht mit meinen #KODI synchen 🤨
Auch der #CertManager läuft jetzt und konnte für ein Testdeployment schon ein #Zertifikat erhalten 🤓
#Nextcloud läuft lokal auch schon...
#ejabberd und #SmartHomeNG steht noch auf der Agenda...
#kubernetes #cluster #Dienste #ansible #deploy #LogitechMediaServer #pihole #UnifiController #jellyfin #kodi #certmanager #zertifikat #nextcloud #ejabberd #SmartHomeNG #MicroK8s
my last few months https://istio.io/latest/docs/ops/common-problems/network-issues/#404-errors-occur-when-multiple-gateways-configured-with-same-tls-certificate FIXED ITTTTT #Istio #kubernetes #certmanager
#Istio #kubernetes #certmanager
🍺 #OriginalMünchnerHell - (% 4,9 vol.) von #Paulaner
Mein "Standardbier", weil a Spezl dort arbat 😁
Während der Beschäftigung mit #Ansible, #MicroK8s, #CertManager, #Ingress 🙈
#Bier #beer #Gerstensaft #Hopfentee #flüssigesBrot #kühlesBlondes #Hopfenkaltschale #beersofmastodon
@beersofmastodon@gup.pe
#OriginalMünchnerHell #Paulaner #ansible #MicroK8s #certmanager #ingress #Bier #beer #Gerstensaft #Hopfentee #flüssigesBrot #kühlesBlondes #Hopfenkaltschale #beersofmastodon
💻🌍 Wenn man zuhause einen #Dienst betreiben möchte, aber keine feste IP hat...
reicht es aus einen CNAME-Eintrag von einer richtigen (Sub)#Domain z.B. cloud.domain.de auf die DYNDNS huabasepp.spdns.org zu setzten...
um dann auch ein #Zertifikat dafür zu bekommen?
#dienst #zertifikat #selfhosting #letsencrypt #acme #certmanager
woo self-signed certificate with #certmanager https://docs.cert-manager.io/en/release-0.11/tasks/issuers/setup-ca.html