# The following manifests contain a self-signed issuer CR and a certificate CR. # More document can be found at https://docs.cert-manager.io # WARNING: Targets CertManager v1.0. Check https://cert-manager.io/docs/installation/upgrading/ for breaking changes. apiVersion: cert-manager.io/v1 kind: Issuer metadata: labels: app.kuberentes.io/name: issuer app.kubernetes.io/instance: selfsigned-issuer app.kubernetes.io/component: certificate app.kubernetes.io/created-by: mashibing-deployment app.kubernetes.io/part-of: mashibing-deployment app.kubernetes.io/managed-by: kustomize name: selfsigned-issuer namespace: system spec: selfSigned: {} --- apiVersion: cert-manager.io/v1 kind: Certificate metadata: labels: app.kubernetes.io/name: certificate app.kubernetes.io/instance: serving-cert app.kubernetes.io/component: certificate app.kubernetes.io/created-by: mashibing-deployment app.kubernetes.io/part-of: mashibing-deployment app.kubernetes.io/managed-by: kustomize name: serving-cert # this name should match the one appeared in kustomizeconfig.yaml namespace: system spec: # $(SERVICE_NAME) and $(SERVICE_NAMESPACE) will be substituted by kustomize dnsNames: - $(SERVICE_NAME).$(SERVICE_NAMESPACE).svc - $(SERVICE_NAME).$(SERVICE_NAMESPACE).svc.cluster.local issuerRef: kind: Issuer name: selfsigned-issuer secretName: webhook-server-cert # this secret will not be prefixed, since it's not managed by kustomize