This commit was merged in pull request #58.
This commit is contained in:
@@ -119,6 +119,10 @@ issuerRef:
|
||||
kind: ClusterIssuer
|
||||
```
|
||||
|
||||
`values.yaml` 必须保持 `config.gatewayAPI.enabled: true`。`bao-acme` 的 HTTP-01
|
||||
solver 通过共享 Gateway 创建临时 HTTPRoute;关闭该项不会让 ClusterIssuer 变为
|
||||
NotReady,而是会让每个 Challenge 卡在 `gateway api is not enabled`。
|
||||
|
||||
Issuance is capped by `default_directory_policy = role:bao-server`
|
||||
(`../../infrastructure/openbao/terraform/pki.tf`), which permits `ad.ddupan.top` subdomains only. Clients
|
||||
need the internal CA in their trust store — already true for the PVE nodes, the DC and
|
||||
|
||||
@@ -44,6 +44,13 @@ cainjector:
|
||||
limits:
|
||||
memory: 256Mi
|
||||
|
||||
# bao-acme solves HTTP-01 through the shared Gateway. The ClusterIssuer can be
|
||||
# accepted while this is disabled, but every Challenge then stays pending with
|
||||
# "gateway api is not enabled". Gateway API CRDs are installed by Envoy Gateway.
|
||||
config:
|
||||
gatewayAPI:
|
||||
enabled: true
|
||||
|
||||
# ⚠ DNS-01 self-check: cert-manager polls authoritative NS for the _acme-challenge
|
||||
# TXT record before telling the CA to validate. By default it asks the cluster's
|
||||
# resolver, which for ad.ddupan.top is CoreDNS -> the Samba AD DC (k3s/coredns-custom.yaml).
|
||||
|
||||
Reference in New Issue
Block a user