Documentation
¶
Index ¶
- Constants
- func ACMETLSDNSNames() []string
- func ApplyClusterIssuerWithKubectl(kubectl core.KubectlRunner) error
- func ApplyLetsEncryptClusterIssuer(kubectl core.KubectlRunner, email string, staging bool, logger *zap.Logger) error
- func ApplyRegistryCertificate(kubectl core.KubectlRunner, dnsNames, ipAddresses []string, issuerName string) error
- func ApplyRegistryCertificateForACME(kubectl core.KubectlRunner, dnsNames []string, issuerName string) error
- func ApplyRegistryCertificateWithKubectl(kubectl core.KubectlRunner) error
- func ApplyRegistryInternalCertificate(kubectl core.KubectlRunner, dnsNames, ipAddresses []string, issuerName string) error
- func CertManagerInstallManifestURL() string
- func CheckCASecretWithKubectl(kubectl core.KubectlRunner) error
- func CheckCertManagerInstalledWithKubectl(kubectl core.KubectlRunner) error
- func CheckCertificateWithKubectl(kubectl core.KubectlRunner, name, namespace string) error
- func CheckClusterIssuerWithKubectl(kubectl core.KubectlRunner) error
- func CheckNamedClusterIssuerWithKubectl(kubectl core.KubectlRunner, name string) error
- func CheckRegistryCertificateOwnershipWithKubectl(kubectl core.KubectlRunner) error
- func ClusterIssuerNameForACME(staging bool) string
- func EnsureCASecretWithKubectl(kubectl core.KubectlRunner) (bool, error)
- func EnsureCertManagerInstalled(kubectl core.KubectlRunner, logger *zap.Logger) error
- func PreflightACMEHostnamesPort80(dnsNames []string)
- func RemoveRegistryIngressShimAnnotationWithKubectl(kubectl core.KubectlRunner) error
- func RenderCertificate(certName, secretName, namespace string, dnsNames, ipAddresses []string, ...) string
- func RenderGeneratedCASecretManifest(now time.Time) (string, error)
- func RenderLetsEncryptClusterIssuerManifest(name, email, serverURL string) string
- func RenderRegistryCertificate(certName, secretName string, dnsNames, ipAddresses []string, issuerName string) string
- func ValidateACMEHostnameForPublicCA() error
- func ValidateACMEHostnamesForPublicCA(hosts ...string) error
- func ValidateIngressManifestForACME(ingressManifest string) error
- func WaitForCertificateReadyWithKubectl(kubectl core.KubectlRunner, name, namespace string, timeout time.Duration) error
- func WaitForTraefikDeploymentForACME(kubectl core.KubectlRunner) error
- type CAHealth
- type CertManager
Constants ¶
const ( CertClusterIssuerName = certClusterIssuerName CertCASecretName = certCASecretName CertManagerNamespace = certManagerNamespace RegistryCertificateName = registryCertificateName RegistryTLSSecretName = registryTLSSecretName RegistryInternalCertificateName = registryInternalCertificateName RegistryInternalTLSSecretName = registryInternalTLSSecretName )
const MinCARemainingLifetime = 180 * 24 * time.Hour
MinCARemainingLifetime is the minimum remaining root lifetime accepted for the bundled workload CA in production. Below this, operators must plan a dual-trust rotation (docs/cli-reference.md, "Bundled workload CA lifecycle") before setup will treat the CA as healthy.
Variables ¶
This section is empty.
Functions ¶
func ACMETLSDNSNames ¶
func ACMETLSDNSNames() []string
func ApplyClusterIssuerWithKubectl ¶
func ApplyClusterIssuerWithKubectl(kubectl core.KubectlRunner) error
func ApplyRegistryCertificate ¶
func ApplyRegistryCertificate(kubectl core.KubectlRunner, dnsNames, ipAddresses []string, issuerName string) error
func ApplyRegistryCertificateForACME ¶
func ApplyRegistryCertificateForACME(kubectl core.KubectlRunner, dnsNames []string, issuerName string) error
func ApplyRegistryCertificateWithKubectl ¶
func ApplyRegistryCertificateWithKubectl(kubectl core.KubectlRunner) error
func ApplyRegistryInternalCertificate ¶
func ApplyRegistryInternalCertificate(kubectl core.KubectlRunner, dnsNames, ipAddresses []string, issuerName string) error
func CertManagerInstallManifestURL ¶
func CertManagerInstallManifestURL() string
func CheckCASecretWithKubectl ¶
func CheckCASecretWithKubectl(kubectl core.KubectlRunner) error
func CheckCertManagerInstalledWithKubectl ¶
func CheckCertManagerInstalledWithKubectl(kubectl core.KubectlRunner) error
func CheckCertificateWithKubectl ¶
func CheckCertificateWithKubectl(kubectl core.KubectlRunner, name, namespace string) error
func CheckClusterIssuerWithKubectl ¶
func CheckClusterIssuerWithKubectl(kubectl core.KubectlRunner) error
func CheckNamedClusterIssuerWithKubectl ¶
func CheckNamedClusterIssuerWithKubectl(kubectl core.KubectlRunner, name string) error
func CheckRegistryCertificateOwnershipWithKubectl ¶
func CheckRegistryCertificateOwnershipWithKubectl(kubectl core.KubectlRunner) error
func ClusterIssuerNameForACME ¶
ClusterIssuerNameForACME returns the ClusterIssuer resource name for Let's Encrypt.
func EnsureCASecretWithKubectl ¶
func EnsureCASecretWithKubectl(kubectl core.KubectlRunner) (bool, error)
func EnsureCertManagerInstalled ¶
func EnsureCertManagerInstalled(kubectl core.KubectlRunner, logger *zap.Logger) error
func PreflightACMEHostnamesPort80 ¶
func PreflightACMEHostnamesPort80(dnsNames []string)
func RemoveRegistryIngressShimAnnotationWithKubectl ¶
func RemoveRegistryIngressShimAnnotationWithKubectl(kubectl core.KubectlRunner) error
func RenderCertificate ¶
func RenderCertificate(certName, secretName, namespace string, dnsNames, ipAddresses []string, issuerName string) string
RenderCertificate renders a cert-manager Certificate in an arbitrary namespace. It is used for namespace-local ingress certificates whose Secret cannot be referenced from another namespace.
func ValidateACMEHostnameForPublicCA ¶
func ValidateACMEHostnameForPublicCA() error
func ValidateACMEHostnamesForPublicCA ¶
ValidateACMEHostnamesForPublicCA validates additional hostnames that are issued by namespace-local Certificates rather than the unified registry Certificate.
func WaitForTraefikDeploymentForACME ¶
func WaitForTraefikDeploymentForACME(kubectl core.KubectlRunner) error
Types ¶
type CAHealth ¶
type CAHealth struct {
Subject string
NotAfter time.Time
Remaining time.Duration
// NearExpiry is true when Remaining is below MinCARemainingLifetime.
NearExpiry bool
}
CAHealth describes a validated CA keypair. It never carries key material.
func ValidateCAKeyPair ¶
ValidateCAKeyPair checks that certPEM/keyPEM form a usable CA: parseable, matching, CA-constrained with certSign usage, within its validity window. Errors never include key material. Near-expiry is reported, not an error, so callers can choose policy (fail in production, warn in test mode).
type CertManager ¶
type CertManager struct {
// contains filtered or unexported fields
}
CertManager manages cert-manager resources for the platform.
func NewCertManager ¶
func NewCertManager(kubectl core.KubectlRunner, logger *zap.Logger) *CertManager
NewCertManager creates a CertManager with the given dependencies.
func (*CertManager) Apply ¶
func (m *CertManager) Apply(dryRun bool) error
Apply installs cert-manager resources required for registry TLS. When dryRun is true, the read-only preflight checks still run (to catch obvious problems like missing cert-manager) but no kubectl apply is performed.
func (*CertManager) Status ¶
func (m *CertManager) Status() error
Status verifies cert-manager installation and required resources.