This commit is contained in:
@@ -119,6 +119,10 @@ issuerRef:
|
|||||||
kind: ClusterIssuer
|
kind: ClusterIssuer
|
||||||
```
|
```
|
||||||
|
|
||||||
|
`values.yaml` 必须保持 `config.gatewayAPI.enabled: true`。`bao-acme` 的 HTTP-01
|
||||||
|
solver 通过共享 Gateway 创建临时 HTTPRoute;关闭该项不会让 ClusterIssuer 变为
|
||||||
|
NotReady,而是会让每个 Challenge 卡在 `gateway api is not enabled`。
|
||||||
|
|
||||||
Issuance is capped by `default_directory_policy = role:bao-server`
|
Issuance is capped by `default_directory_policy = role:bao-server`
|
||||||
(`../../infrastructure/openbao/terraform/pki.tf`), which permits `ad.ddupan.top` subdomains only. Clients
|
(`../../infrastructure/openbao/terraform/pki.tf`), which permits `ad.ddupan.top` subdomains only. Clients
|
||||||
need the internal CA in their trust store — already true for the PVE nodes, the DC and
|
need the internal CA in their trust store — already true for the PVE nodes, the DC and
|
||||||
|
|||||||
@@ -44,6 +44,13 @@ cainjector:
|
|||||||
limits:
|
limits:
|
||||||
memory: 256Mi
|
memory: 256Mi
|
||||||
|
|
||||||
|
# bao-acme solves HTTP-01 through the shared Gateway. The ClusterIssuer can be
|
||||||
|
# accepted while this is disabled, but every Challenge then stays pending with
|
||||||
|
# "gateway api is not enabled". Gateway API CRDs are installed by Envoy Gateway.
|
||||||
|
config:
|
||||||
|
gatewayAPI:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
# ⚠ DNS-01 self-check: cert-manager polls authoritative NS for the _acme-challenge
|
# ⚠ DNS-01 self-check: cert-manager polls authoritative NS for the _acme-challenge
|
||||||
# TXT record before telling the CA to validate. By default it asks the cluster's
|
# TXT record before telling the CA to validate. By default it asks the cluster's
|
||||||
# resolver, which for ad.ddupan.top is CoreDNS -> the Samba AD DC (k3s/coredns-custom.yaml).
|
# resolver, which for ad.ddupan.top is CoreDNS -> the Samba AD DC (k3s/coredns-custom.yaml).
|
||||||
|
|||||||
Reference in New Issue
Block a user