certmanager

package
v0.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Index

Constants

View Source
const (
	CertClusterIssuerName           = certClusterIssuerName
	CertCASecretName                = certCASecretName
	CertManagerNamespace            = certManagerNamespace
	RegistryCertificateName         = registryCertificateName
	RegistryTLSSecretName           = registryTLSSecretName
	RegistryInternalCertificateName = registryInternalCertificateName
	RegistryInternalTLSSecretName   = registryInternalTLSSecretName
)
View Source
const MinCARemainingLifetime = 180 * 24 * time.Hour

MinCARemainingLifetime is the minimum remaining root lifetime accepted for the bundled workload CA in production. Below this, operators must plan a dual-trust rotation (docs/cli-reference.md, "Bundled workload CA lifecycle") before setup will treat the CA as healthy.

Variables

This section is empty.

Functions

func ACMETLSDNSNames

func ACMETLSDNSNames() []string

func ApplyClusterIssuerWithKubectl

func ApplyClusterIssuerWithKubectl(kubectl core.KubectlRunner) error

func ApplyLetsEncryptClusterIssuer

func ApplyLetsEncryptClusterIssuer(kubectl core.KubectlRunner, email string, staging bool, logger *zap.Logger) error

func ApplyRegistryCertificate

func ApplyRegistryCertificate(kubectl core.KubectlRunner, dnsNames, ipAddresses []string, issuerName string) error

func ApplyRegistryCertificateForACME

func ApplyRegistryCertificateForACME(kubectl core.KubectlRunner, dnsNames []string, issuerName string) error

func ApplyRegistryCertificateWithKubectl

func ApplyRegistryCertificateWithKubectl(kubectl core.KubectlRunner) error

func ApplyRegistryInternalCertificate

func ApplyRegistryInternalCertificate(kubectl core.KubectlRunner, dnsNames, ipAddresses []string, issuerName string) error

func CertManagerInstallManifestURL

func CertManagerInstallManifestURL() string

func CheckCASecretWithKubectl

func CheckCASecretWithKubectl(kubectl core.KubectlRunner) error

func CheckCertManagerInstalledWithKubectl

func CheckCertManagerInstalledWithKubectl(kubectl core.KubectlRunner) error

func CheckCertificateWithKubectl

func CheckCertificateWithKubectl(kubectl core.KubectlRunner, name, namespace string) error

func CheckClusterIssuerWithKubectl

func CheckClusterIssuerWithKubectl(kubectl core.KubectlRunner) error

func CheckNamedClusterIssuerWithKubectl

func CheckNamedClusterIssuerWithKubectl(kubectl core.KubectlRunner, name string) error

func CheckRegistryCertificateOwnershipWithKubectl

func CheckRegistryCertificateOwnershipWithKubectl(kubectl core.KubectlRunner) error

func ClusterIssuerNameForACME

func ClusterIssuerNameForACME(staging bool) string

ClusterIssuerNameForACME returns the ClusterIssuer resource name for Let's Encrypt.

func EnsureCASecretWithKubectl

func EnsureCASecretWithKubectl(kubectl core.KubectlRunner) (bool, error)

func EnsureCertManagerInstalled

func EnsureCertManagerInstalled(kubectl core.KubectlRunner, logger *zap.Logger) error

func PreflightACMEHostnamesPort80

func PreflightACMEHostnamesPort80(dnsNames []string)

func RemoveRegistryIngressShimAnnotationWithKubectl

func RemoveRegistryIngressShimAnnotationWithKubectl(kubectl core.KubectlRunner) error

func RenderCertificate

func RenderCertificate(certName, secretName, namespace string, dnsNames, ipAddresses []string, issuerName string) string

RenderCertificate renders a cert-manager Certificate in an arbitrary namespace. It is used for namespace-local ingress certificates whose Secret cannot be referenced from another namespace.

func RenderGeneratedCASecretManifest

func RenderGeneratedCASecretManifest(now time.Time) (string, error)

func RenderLetsEncryptClusterIssuerManifest

func RenderLetsEncryptClusterIssuerManifest(name, email, serverURL string) string

func RenderRegistryCertificate

func RenderRegistryCertificate(certName, secretName string, dnsNames, ipAddresses []string, issuerName string) string

func ValidateACMEHostnameForPublicCA

func ValidateACMEHostnameForPublicCA() error

func ValidateACMEHostnamesForPublicCA

func ValidateACMEHostnamesForPublicCA(hosts ...string) error

ValidateACMEHostnamesForPublicCA validates additional hostnames that are issued by namespace-local Certificates rather than the unified registry Certificate.

func ValidateIngressManifestForACME

func ValidateIngressManifestForACME(ingressManifest string) error

func WaitForCertificateReadyWithKubectl

func WaitForCertificateReadyWithKubectl(kubectl core.KubectlRunner, name, namespace string, timeout time.Duration) error

func WaitForTraefikDeploymentForACME

func WaitForTraefikDeploymentForACME(kubectl core.KubectlRunner) error

Types

type CAHealth

type CAHealth struct {
	Subject   string
	NotAfter  time.Time
	Remaining time.Duration
	// NearExpiry is true when Remaining is below MinCARemainingLifetime.
	NearExpiry bool
}

CAHealth describes a validated CA keypair. It never carries key material.

func ValidateCAKeyPair

func ValidateCAKeyPair(certPEM, keyPEM []byte, now time.Time) (CAHealth, error)

ValidateCAKeyPair checks that certPEM/keyPEM form a usable CA: parseable, matching, CA-constrained with certSign usage, within its validity window. Errors never include key material. Near-expiry is reported, not an error, so callers can choose policy (fail in production, warn in test mode).

type CertManager

type CertManager struct {
	// contains filtered or unexported fields
}

CertManager manages cert-manager resources for the platform.

func NewCertManager

func NewCertManager(kubectl core.KubectlRunner, logger *zap.Logger) *CertManager

NewCertManager creates a CertManager with the given dependencies.

func (*CertManager) Apply

func (m *CertManager) Apply(dryRun bool) error

Apply installs cert-manager resources required for registry TLS. When dryRun is true, the read-only preflight checks still run (to catch obvious problems like missing cert-manager) but no kubectl apply is performed.

func (*CertManager) Status

func (m *CertManager) Status() error

Status verifies cert-manager installation and required resources.

func (*CertManager) Wait

func (m *CertManager) Wait(timeout time.Duration) error

Wait blocks until the registry certificate is Ready or times out.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL