cert-manager
TLS certificate management with cert-manager
This guide shows you how to install cert-manager for TLS certificate management. The guide assumes a new or fresh MinIO Operator installation.
Note
This guide uses a self-signed Cluster Issuer. You can also use other Issuers supported by cert-manager.
The main difference is that you must provide that Issuer CA certificate to MinIO, instead of the CA’s mentioned in this guide.
Refer to the cert-manager documentation and your own organization’s certificate requirements for more advanced configurations.
cert-manager manages certificates within Kubernetes clusters. The MinIO Operator supports using cert-manager for managing and provisioning certificates as an alternative to the MinIO Operator managing certificates for itself and its tenants.
cert-manager obtains valid certificates from an Issuer or ClusterIssuer and can automatically renew certificates prior to expiration.
A ClusterIssuer issues certificates for multiple namespaces. An Issuer only mints certificates for its own namespace.
The following graphic depicts how cert-manager provides certificates in namespaces across a Kubernetes cluster.
- A
ClusterIssuerexists at the root level of the Kubernetes cluster, typically thedefaultnamespace, to provide certificates to all other namespaces. - The
minio-operatornamespace receives its own, localIssuer. - Each tenant’s namespace receives its own, local
Issuer. - The certificates issued by each tenant namespace must be made known to and trusted by the MinIO Operator.
Prerequisites
- A supported version of Kubernetes.
- kustomize installed
kubectlaccess to yourk8scluster
Setup cert-manager
Install cert-manager
The following command installs version 1.12.13 using kubectl.
Release 1.12.X LTS is preferred, but you may install the latest version. For more details on installing cert-manager, see their installation instructions.
Create a self-signed Cluster Issuer for the cluster
The Cluster Issuer is the top level Issuer from which all other certificates in the cluster derive.
-
Request cert-manager to generate this by creating a
ClusterIssuerresource.Create a file called
selfsigned-root-clusterissuer.yamlwith the following contents: -
Apply the resource to the cluster:
Next steps
Set up cert-manager for the MinIO Operator.