Show HN: Kubernetes Certificate Manager – Native Let's Encrypt Integration
github.com
github.com
Interestingly, kube-lego requires DNS to be configured correctly anyway so that lego can verify the http challenge (implicitly requiring the DNS A record). kube-cert-manager though, could retrieve the cert automatically before the A record is ever created and propagated.
AFIACT you still have to configure the DNS A record yourself, kube-cert-manager just solves the challenges using DNS.
The goal is to push all DNS providers, including the Google DNS provider, to exec plugins that live out of tree. To ease deployments the "official" Kubernetes Certificate Manager container will include a few DNS providers via exec plugins out of the box. There will be instructions on how to build new containers with additional providers for custom deployments. More details soon.
See the proposed exec based plugin model: https://github.com/kelseyhightower/dns01-exec-plugins
https://github.com/kelseyhightower/kube-cert-manager/blob/ma...
Current goals are to vet the idea of using DNS-01 challenges and get the UX right.
Also, lego is a bit cumbersome to run in a container. It relies on storing config and certs in a .lego dir in the home directory, and doesn't clean up DNS entries if it somehow fails to run so it would be a pain to use without modification.
I think they should be possible to support with no or minimal changes to the API you have in the GCE provider currently. Mostly just need to make changes around the service-account/secret handling, I believe.
Also great work Kelsey on providing a solid example of how to structure a complex k8s integration.