diff --git a/etc/README.md b/etc/README.md index 3ff8d9a0..5d0853e9 100644 --- a/etc/README.md +++ b/etc/README.md @@ -8,7 +8,7 @@ OR helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx helm repo update -helm install ingress-nginx ingress-nginx/ingress-nginx +helm upgrade --install --version=4.0.19 ingress-nginx ingress-nginx/ingress-nginx ``` * Install [Helm](https://helm.sh/docs/intro/install/) for running helm charts diff --git a/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml b/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml index fad0cb65..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/administration/templates/administration-ingress.yaml @@ -3,18 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - {{- if eq .Release.Name "es-st" }} - cert-manager.io/cluster-issuer: eshop-issuer - {{- end }} - {{- if eq .Release.Name "es-az" }} - cert-manager.io/issuer: letsencrypt - {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/administration/values.yaml b/etc/k8s/eshoponabp/charts/administration/values.yaml index 3a6e31d8..05e9d62c 100644 --- a/etc/k8s/eshoponabp/charts/administration/values.yaml +++ b/etc/k8s/eshoponabp/charts/administration/values.yaml @@ -26,7 +26,7 @@ synchedCommunication: ingress: host: eshop-st-administration - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-administration diff --git a/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml b/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml index a24245ba..30e7e89e 100644 --- a/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/authserver/templates/authserver-ingress.yaml @@ -3,25 +3,18 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" nginx.ingress.kubernetes.io/configuration-snippet: | more_set_input_headers "from-ingress: true"; - # cert-manager.io/cluster-issuer: selfsigned-issuer - # {{- if eq .Release.Name "es-st" }} - # cert-manager.io/cluster-issuer: eshop-issuer - # {{- end }} - # {{- if eq .Release.Name "es-az" }} - # cert-manager.io/issuer: letsencrypt - # {{- end }} spec: + ingressClassName: nginx tls: - hosts: - "eshop-st-authserver" - secretName: "eshop-test-tls" + secretName: "eshop-wildcard-tls" rules: - host: "{{ .Values.ingress.host }}" http: diff --git a/etc/k8s/eshoponabp/charts/authserver/values.yaml b/etc/k8s/eshoponabp/charts/authserver/values.yaml index a1b3edb6..c498a1ea 100644 --- a/etc/k8s/eshoponabp/charts/authserver/values.yaml +++ b/etc/k8s/eshoponabp/charts/authserver/values.yaml @@ -18,7 +18,7 @@ config: ingress: host: eshop-st-authserver - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/app-authserver diff --git a/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml b/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml index 7f7ab322..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/basket/templates/basket-ingress.yaml @@ -3,14 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/issuer: eshop-issuer - # cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/basket/values.yaml b/etc/k8s/eshoponabp/charts/basket/values.yaml index f332621a..c69ad16a 100644 --- a/etc/k8s/eshoponabp/charts/basket/values.yaml +++ b/etc/k8s/eshoponabp/charts/basket/values.yaml @@ -19,7 +19,7 @@ config: ingress: host: eshop-st-basket - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-basket diff --git a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml index 774a82c0..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/templates/catalog-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - # cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/catalog/values.yaml b/etc/k8s/eshoponabp/charts/catalog/values.yaml index 970e0e02..8e65d499 100644 --- a/etc/k8s/eshoponabp/charts/catalog/values.yaml +++ b/etc/k8s/eshoponabp/charts/catalog/values.yaml @@ -23,7 +23,7 @@ config: ingress: host: eshop-st-catalog - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-catalog diff --git a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml index 9bcfa428..a8d988f6 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web-public/templates/gateway-web-public-ingress.yaml @@ -3,16 +3,15 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: eshop-issuer {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml b/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml index bb625762..1b30388b 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web-public/values.yaml @@ -28,7 +28,7 @@ reRoutes: ingress: host: eshop-st-gateway-web-public - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/gateway-web-public diff --git a/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml b/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml index 8e106909..0dedb3d3 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web/templates/gateway-web-ingress.yaml @@ -3,16 +3,15 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/gateway-web/values.yaml b/etc/k8s/eshoponabp/charts/gateway-web/values.yaml index 4e3ac302..49ac9ace 100644 --- a/etc/k8s/eshoponabp/charts/gateway-web/values.yaml +++ b/etc/k8s/eshoponabp/charts/gateway-web/values.yaml @@ -21,7 +21,7 @@ reRoutes: url: http://eshop-st-administration ingress: host: # eshop-st-gateway-web - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/gateway-web diff --git a/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml b/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml index e8030dea..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/identity/templates/identity-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: selfsigned-issuer spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/identity/values.yaml b/etc/k8s/eshoponabp/charts/identity/values.yaml index 842fe3ee..34324d0b 100644 --- a/etc/k8s/eshoponabp/charts/identity/values.yaml +++ b/etc/k8s/eshoponabp/charts/identity/values.yaml @@ -32,7 +32,7 @@ identityServerClients: ingress: host: eshop-st-identity - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-identity diff --git a/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml b/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml index e843265f..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/ordering/templates/ordering-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/ordering/values.yaml b/etc/k8s/eshoponabp/charts/ordering/values.yaml index 895834ba..c9f8a55b 100644 --- a/etc/k8s/eshoponabp/charts/ordering/values.yaml +++ b/etc/k8s/eshoponabp/charts/ordering/values.yaml @@ -17,7 +17,7 @@ config: ingress: host: eshop-st-ordering - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-ordering diff --git a/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml b/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml index e843265f..de94cec3 100644 --- a/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/payment/templates/payment-ingress.yaml @@ -3,13 +3,12 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/payment/values.yaml b/etc/k8s/eshoponabp/charts/payment/values.yaml index 3d5a55d7..37ffd9cb 100644 --- a/etc/k8s/eshoponabp/charts/payment/values.yaml +++ b/etc/k8s/eshoponabp/charts/payment/values.yaml @@ -17,7 +17,7 @@ config: ingress: host: eshop-st-payment - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/service-payment diff --git a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml index ec4080bc..18a5ed2f 100644 --- a/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/public-web/templates/public-web-ingress.yaml @@ -3,16 +3,15 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/public-web/values.yaml b/etc/k8s/eshoponabp/charts/public-web/values.yaml index ba4f9861..7d38cb1f 100644 --- a/etc/k8s/eshoponabp/charts/public-web/values.yaml +++ b/etc/k8s/eshoponabp/charts/public-web/values.yaml @@ -12,7 +12,7 @@ config: ingress: host: eshop-st-public-web - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/app-publicweb diff --git a/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml b/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml index 54a62c3c..bbade7db 100644 --- a/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml +++ b/etc/k8s/eshoponabp/charts/web/templates/web-ingress.yaml @@ -3,16 +3,15 @@ kind: Ingress metadata: name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress annotations: - kubernetes.io/ingress.class: "nginx" nginx.ingress.kubernetes.io/rewrite-target: / nginx.ingress.kubernetes.io/force-ssl-redirect: "true" nginx.ingress.kubernetes.io/proxy-buffer-size: 32k nginx.ingress.kubernetes.io/proxy-buffers-number: "8" - cert-manager.io/cluster-issuer: letsencrypt {{- if eq .Release.Name "es-az" }} nginx.ingress.kubernetes.io/from-to-www-redirect: "true" {{- end }} spec: + ingressClassName: nginx tls: - hosts: - {{ .Values.ingress.host }} diff --git a/etc/k8s/eshoponabp/charts/web/values.yaml b/etc/k8s/eshoponabp/charts/web/values.yaml index 792ef099..9a3418b7 100644 --- a/etc/k8s/eshoponabp/charts/web/values.yaml +++ b/etc/k8s/eshoponabp/charts/web/values.yaml @@ -7,7 +7,7 @@ config: ingress: host: eshop-st-web - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: eshoponabp/app-web diff --git a/etc/k8s/eshoponabp/values.yaml b/etc/k8s/eshoponabp/values.yaml index 81bc1014..6e31550c 100644 --- a/etc/k8s/eshoponabp/values.yaml +++ b/etc/k8s/eshoponabp/values.yaml @@ -13,7 +13,7 @@ authserver: elasticsearchHost: es-st-elasticsearch ingress: host: eshop-st-authserver - tlsSecret: eshop-staging-tls + tlsSecret: eshop-wildcard-tls image: repository: "eshoponabp/app-authserver" tag: latest diff --git a/etc/k8s/tls-cert/eshop-demo-tls.conf b/etc/k8s/tls-cert/eshop-demo-tls.conf deleted file mode 100644 index 68e574ef..00000000 --- a/etc/k8s/tls-cert/eshop-demo-tls.conf +++ /dev/null @@ -1,38 +0,0 @@ -[req] -default_bits = 2048 -default_keyfile = eshop-st.key -distinguished_name = req_distinguished_name -req_extensions = req_ext -x509_extensions = v3_ca - -[req_distinguished_name] -commonName = Common Name (e.g. server FQDN or YOUR name) -commonName_default = eshoponabp -commonName_max = 64 - -[req_ext] -subjectAltName = @alt_names - -[v3_ca] -subjectAltName = @alt_names -basicConstraints = critical, CA:false -keyUsage = keyCertSign, cRLSign, digitalSignature,keyEncipherment - -[alt_names] -DNS.1 = eshop-st-web -DNS.2 = eshop-st-public-web -DNS.3 = eshop-st-authserver -DNS.4 = eshop-st-identity -DNS.5 = eshop-st-administration -DNS.6 = eshop-st-gateway-web -DNS.7 = eshop-st-gateway-web-public -DNS.8 = eshop-st-basket -DNS.9 = eshop-st-catalog -DNS.10 = eshop-st-ordering -DNS.11 = eshop-st-payment - -# Generate certificate from config -# Use the command: -# 'openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout eshop-st-cert.key -out eshop-st-cert.pem -config eshop-demo-tls.conf' -# Verify that you have eshop-st-cert.crt and eshop-st-cert.key files under k8s/tls-cert folder -# Run comand : 'kubectl create secret tls eshop-demo-tls --cert=eshop-st-cert.pem --key=eshop-st-cert.key --namespace=eshop' diff --git a/etc/k8s/tls-cert/eshop-st-cert.key b/etc/k8s/tls-cert/eshop-st-cert.key deleted file mode 100644 index fffab06a..00000000 --- a/etc/k8s/tls-cert/eshop-st-cert.key +++ /dev/null @@ -1,28 +0,0 @@ ------BEGIN PRIVATE KEY----- -MIIEvwIBADANBgkqhkiG9w0BAQEFAASCBKkwggSlAgEAAoIBAQDSgXYuFacjDRuc -yj6oqIV1KlBinfbqnH9xEFOQXN6vFI9v5TzOTXstjCVQKhPWDCw3WSw7ydlAodFa -djeXEjapDGQmAVJk5nmPLv+UCOrZHd6ut8QEMb1cAGtOR71d8CVjWuZx6igGTPTQ -m2efRip0B0mog4j5vc+q8tr0qu+h13TAkivYGPQTvT46p/GypH5xFjAVw9P6IIYP -fr+nm2R/fUV3FEmaUBJmNjjoDJzrtGxe8zWD7vRxIYoNeffzRTMCT622Y8j6TEp2 -rlVPjh9Dp7+Wrj6FxopKBt6j3F5S1NKkEgEID8cL1Aufu0Xk/dWPsSAstVPgA/gf -GIW+7ALHAgMBAAECggEBAL2lmvYL1ecTMRRBdM/3+zxCYedmzwQw9/PBtLczo/9x -84Por65hSZ8QSrF9Jx/JGbDHqr02rX64CmeIZ6633vzPyA4hVLzIky13NxSEMCho -66zWrEbnFOUlD4eXxDg0WUq4ozJvtZ1viYPC7kklKqwbwLWLw0TUR5qIbtDMi1Vu -pyfm2YUtjqx2JPjD2i5juZx3XbgiqncpyRDroY80IqOZ/Kp83eMdst9wyfJaAy0B -kxZjvU1U2exD/l9RxKKreES2Vrbn+PvF3ttTgz/hE1ScBBfMB9kn+37esGZVByjb -ER0GFgt0jOx2ok+n2+zm2Z68IjoYDvsNo586tHoXxrECgYEA75UD5Nt9joCpCWVd -zXBQ8OUJwRU/N74RjBBS/NTT2sZ+q7xYxDx3xPwhyHXI+wwaHClGUE0yx5mrqqON -p3ELpanYdLWcdA6f/bFuuSNOAi7XSc1wCbNkTh5yxIyqWMvEYXqAj1/5T1VJ6+xU -pyKUe1588WKpSURrtGRxu0rKizkCgYEA4O5cJQmBeTlx++iVtONZv7HB371rYt45 -0nkBKfBJOjsVd2sB5f6ry5PaRcJyXamF7QYGgm4xo+KvrfHrf+JjebiJR46tsK0n -y130XjZVi28HPGBUG610zXOH3FgUQiSVbRulG0wzTtFHzdbVHJuTmA65+BZnayhM -WICqyiw0/f8CgYEAuXLmbbr8iFbNAYnmPwSGksEneL7ijVphqMJmCnEPgBQPrw1+ -xH9t0hu8ZrfNl435k/zbAYOQH/Kyb8Zj+s1FT7mV5FlDvo4nh69VXpeWZZgua2FL -LScgKFvnSH79yPgJjc7OPqzyhVcmfikUKb9Zodk064AMO7trh1oMswYkm/kCgYA/ -w/MFYOt+hUWGB4qhTC5+RJNUrWtLDPrRaxJkZEUuJ9/PCdvw6sCjJtgjHJu1Z8Ca -0DF6OmkCL9pj8ogzqedPc3wfeBhPVNdKNOl45+habfBcMmbFrefF8rGaSrH7ikl+ -M+8bjP+ioXu8o+GoiYZO/iXEaf2JiFQUZu2EAQJI2wKBgQCLUuZyV/fx2/90md4W -6GwyMYrA3Z3pVm3WKdphSX8euTTNjOjtwXwZ0iqfGsm0okHC0+DcI9PAhPh99fCB -7miZcUvQmqhmL7rcrOTfPRLVZ9flEVqeq6RCW4ICA2G7+0+eFz87FIl9EHfN9IMU -2mLb5Ph0OuI7W75OBR23qqVk5g== ------END PRIVATE KEY----- diff --git a/etc/k8s/tls-cert/eshop-st-cert.pem b/etc/k8s/tls-cert/eshop-st-cert.pem deleted file mode 100644 index f962d807..00000000 --- a/etc/k8s/tls-cert/eshop-st-cert.pem +++ /dev/null @@ -1,23 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDxjCCAq6gAwIBAgIUavYi4mtz8TCt6EwG/MDNsnykGPMwDQYJKoZIhvcNAQEL -BQAwFTETMBEGA1UEAwwKZXNob3BvbmFicDAeFw0yMjA0MDgxOTAwMDFaFw0yMzA0 -MDgxOTAwMDFaMBUxEzARBgNVBAMMCmVzaG9wb25hYnAwggEiMA0GCSqGSIb3DQEB -AQUAA4IBDwAwggEKAoIBAQDSgXYuFacjDRucyj6oqIV1KlBinfbqnH9xEFOQXN6v -FI9v5TzOTXstjCVQKhPWDCw3WSw7ydlAodFadjeXEjapDGQmAVJk5nmPLv+UCOrZ -Hd6ut8QEMb1cAGtOR71d8CVjWuZx6igGTPTQm2efRip0B0mog4j5vc+q8tr0qu+h -13TAkivYGPQTvT46p/GypH5xFjAVw9P6IIYPfr+nm2R/fUV3FEmaUBJmNjjoDJzr -tGxe8zWD7vRxIYoNeffzRTMCT622Y8j6TEp2rlVPjh9Dp7+Wrj6FxopKBt6j3F5S -1NKkEgEID8cL1Aufu0Xk/dWPsSAstVPgA/gfGIW+7ALHAgMBAAGjggEMMIIBCDCB -6gYDVR0RBIHiMIHfggxlc2hvcC1zdC13ZWKCE2VzaG9wLXN0LXB1YmxpYy13ZWKC -E2VzaG9wLXN0LWF1dGhzZXJ2ZXKCEWVzaG9wLXN0LWlkZW50aXR5ghdlc2hvcC1z -dC1hZG1pbmlzdHJhdGlvboIUZXNob3Atc3QtZ2F0ZXdheS13ZWKCG2VzaG9wLXN0 -LWdhdGV3YXktd2ViLXB1YmxpY4IPZXNob3Atc3QtYmFza2V0ghBlc2hvcC1zdC1j -YXRhbG9nghFlc2hvcC1zdC1vcmRlcmluZ4IQZXNob3Atc3QtcGF5bWVudDAMBgNV -HRMBAf8EAjAAMAsGA1UdDwQEAwIBpjANBgkqhkiG9w0BAQsFAAOCAQEAhJK7TgZw -IVqVbyYHw3M3fH5/tvioZNq0PbYOeWBX/A4ZolE1o5n5wzwk1TcOk7Kg8KdvZPM8 -VZgfx4B/MYaHWmliPx036oB4MJ9zh1D+zPr2kNqUKzY07H1JJDS9BzuBiSnnv7dJ -nuiJnV5F2Uy2cWltCgZ4xZ7xwnlofxIV4EnB88r+Gqz+LNtm1BFF4p5CzSQHcTrc -04H7k7gvITRYq086yuButbYT43uBBVJDEmTWUKMYWgh5K1cbyOUkYmaMCYaUnpNq -tgoZCNrUq3dpv/KsDsxh1bf2W0LsNiu2zExjetqDjoDC4cnCXYOsF7dW0HcnqFCN -PcxxXhW+kcd6+A== ------END CERTIFICATE----- diff --git a/etc/k8s/tls-cert/eshop-test-tls.crt b/etc/k8s/tls-cert/eshop-test-tls.crt deleted file mode 100644 index c3a18d04..00000000 --- a/etc/k8s/tls-cert/eshop-test-tls.crt +++ /dev/null @@ -1,23 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDxjCCAq6gAwIBAgIUWAAiaf6jGeQBXdYnOFUKw+cQIlMwDQYJKoZIhvcNAQEL -BQAwFTETMBEGA1UEAwwKZXNob3BvbmFicDAeFw0yMjA0MDgyMjM4NDVaFw0yMzA0 -MDgyMjM4NDVaMBUxEzARBgNVBAMMCmVzaG9wb25hYnAwggEiMA0GCSqGSIb3DQEB -AQUAA4IBDwAwggEKAoIBAQDaQiJirGIVlbr00M8e1qTWLeIgsMUhLGa8fa/cEMJ7 -uInNm6hkCv1UrxGDKcxBBXs/kt+VYfnjtp+2IBlgv6wbHWftQYEwXxbtvXNIBWIn -GEee9S2uREDm0OHJF/xLEHPvFE15mFeo3bfJ3GIkuXuKu3RzQBre4q2y+1RfHnav -YKF/QIg3oWysnmt5G2wBS7bZvHkjvX7N31g80JU3yYuPkiCJi+PHiQbeyn4Obaf+ -TksoOqrwIO6bYE+cR5v2eLn0nLg/ZYvKSAbmmEiNIja3DRidxM9fYWPQgqVsAGs5 -CqdqH3PX9JNSl2FOQQqPSQ9IUwa5lJogNiSWZVacijh1AgMBAAGjggEMMIIBCDCB -6gYDVR0RBIHiMIHfggxlc2hvcC1zdC13ZWKCE2VzaG9wLXN0LXB1YmxpYy13ZWKC -E2VzaG9wLXN0LWF1dGhzZXJ2ZXKCEWVzaG9wLXN0LWlkZW50aXR5ghdlc2hvcC1z -dC1hZG1pbmlzdHJhdGlvboIUZXNob3Atc3QtZ2F0ZXdheS13ZWKCG2VzaG9wLXN0 -LWdhdGV3YXktd2ViLXB1YmxpY4IPZXNob3Atc3QtYmFza2V0ghBlc2hvcC1zdC1j -YXRhbG9nghFlc2hvcC1zdC1vcmRlcmluZ4IQZXNob3Atc3QtcGF5bWVudDAMBgNV -HRMBAf8EAjAAMAsGA1UdDwQEAwIBpjANBgkqhkiG9w0BAQsFAAOCAQEA0lsXpx1C -ItDk2gwKnUiof90y9iYBIZZ+RyxZlJHXYOTrfzOtg1U5zxZtaTBefPJhjI/hibyu -a2zCUFpc0CBLG8EVzLOv8VJDxiRf93bLP9Eoy40l8MVS8Lt5HVRs8xUiuGvxspwH -7aXAeP0HlykDjt3njwawPRuijFrk2GzQSCkPVh84e7RKTq4TYb1MpRjZw2Q92/NM -v0Zboi7wY0RqakyUHdWpgnWP/5ch8f8mInXkOJiQo0h5fbtrB8UdBGC7Qu1uKgsb -UloHs0w5p0q1AqmtYTJo2FmMP/touls/XhpJ5V0B3X2qh5JISqZiKifkPoJaIKCt -6ivVqCafin3yEQ== ------END CERTIFICATE----- diff --git a/etc/k8s/tls-cert/eshop-test-tls.key b/etc/k8s/tls-cert/eshop-test-tls.key deleted file mode 100644 index 3958be9a..00000000 --- a/etc/k8s/tls-cert/eshop-test-tls.key +++ /dev/null @@ -1,28 +0,0 @@ ------BEGIN PRIVATE KEY----- -MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQDaQiJirGIVlbr0 -0M8e1qTWLeIgsMUhLGa8fa/cEMJ7uInNm6hkCv1UrxGDKcxBBXs/kt+VYfnjtp+2 -IBlgv6wbHWftQYEwXxbtvXNIBWInGEee9S2uREDm0OHJF/xLEHPvFE15mFeo3bfJ -3GIkuXuKu3RzQBre4q2y+1RfHnavYKF/QIg3oWysnmt5G2wBS7bZvHkjvX7N31g8 -0JU3yYuPkiCJi+PHiQbeyn4Obaf+TksoOqrwIO6bYE+cR5v2eLn0nLg/ZYvKSAbm -mEiNIja3DRidxM9fYWPQgqVsAGs5CqdqH3PX9JNSl2FOQQqPSQ9IUwa5lJogNiSW -ZVacijh1AgMBAAECggEAA3CxbA69iQuQI9W6vgiyFnIos001/jzd7bCpefWFqz+Q -ZH5EnDcUISaVRxT8lDXK6IifH5Koxq8VO2CsJbs/sjm3bqTurV2CVgL7czIqhuU6 -E8ZXjvyibUDzniDTqDc9LJKMWhNNpmrAP91KarvFt70Wq85h3guCo2SUwt8PDdqX -nHw0QzBXfkvg9/b90XCXrR/LnIyQ271wONJ1t1updDeo/EZzj/77yFWrvO7zw734 -FqDpfY+VeD9YNQszU40J/CMZa2qKqBXNp68JL2xOSFeHqNKvwKWvP145uGjURblz -Z12NdoKE3WbzMyv9zO1IdocaL1bFtM+7t3B9KFIbQQKBgQDz9ip8+AOTHp3RywUa -PvVGSk3U8+PBX3tTXgmoeRbMJ+xffE8uHMDu710izEvbkxQhAgar5dJH8NiragvW -LVZXCnstJfGI1V3oXnB2Y4BEB1ZTVSV8fuYutm6UhudWebTMg9EndvixK088pjya -GX0nx4MXOWgBo7vgLNXDNQa40QKBgQDlB0XvpJQEBZurz04iEgjXuXHttGQr4kw8 -0DwC2KA1JnEqZFy4CNGQyyIAKG9xDGCeejbwzBXkamPXpZ4Q7/Opv3wbsxzCnZE3 -MX6XUKqx2CfG7lRWwmLybLvRynHhT6LlWouNil/pHKvdv8LF+pu68S7sK24CaMpu -QF8aREHuZQKBgQDBnWBjBcJwhB/kXCeUiNrICjhzBYx/73NE2qD3oAJDzHt/3HxK -sG8+MaHM+C5L+RJEkAMTcbXNeou6ntL+C8U2Fw9i6XYjjpKU1D6U9qrZUqlkQXMa -tuufrxFbtyTqMHUYypS3qWf9081y6Mu30PrPEzwqtlig1H1KkMqlvfOzwQKBgFLS -soPbLHvX21fifAruIqyAr6aama8VAyTq2QjedfFCmaIO8UjMR5zpGL6d4M8s/rPQ -1pV1+GTF5J1TkznkzGUSjjsmJrxqZt1i1Li7vz7ZQGk8PtuxKD8q+zD+2Pf16J6w -g88Hv295ot1qP3GBE1gjaCiX/Ax7ANmmBb5l+MHRAoGAY6MXc6EUdgcLq0p/FbNk -OloFD/iUGNsJfSMxMg3vpWP9PhTSToiVDJrsviFWl2+z4CNicptsqfji237Uu4TP -d8Br0flNjfgyZ6BeRl1Ovgls6hDVgvjl6VWghZw9TfA0pc1ozb5FnUQkTG3+ceBY -KlHxDmv2VwadB8QbmuHqKjc= ------END PRIVATE KEY----- diff --git a/etc/k8s/tls-cert/ingress-tls.yaml b/etc/k8s/tls-cert/ingress-tls.yaml deleted file mode 100644 index f888087d..00000000 --- a/etc/k8s/tls-cert/ingress-tls.yaml +++ /dev/null @@ -1,24 +0,0 @@ -apiVersion: networking.k8s.io/v1 -kind: Ingress -metadata: - name: kuard - annotations: - kubernetes.io/ingress.class: "nginx" - cert-manager.io/issuer: "letsencrypt-staging" - -spec: - tls: - - hosts: - - example.example.com - secretName: quickstart-example-tls - rules: - - host: example.example.com - http: - paths: - - path: / - pathType: Prefix - backend: - service: - name: kuard - port: - number: 80 diff --git a/etc/k8s/tls-cert/notes.md b/etc/k8s/tls-cert/notes.md index 9b9fae8e..7119f417 100644 --- a/etc/k8s/tls-cert/notes.md +++ b/etc/k8s/tls-cert/notes.md @@ -1,49 +1,26 @@ # Notes -## Creating demo tls cert +## TODO: - section on mkcert -``` -kubectl create secret tls eshop-demo-tls \ - --cert=eshop-st-cert.pem \ - --key=eshop-st-key.pem -``` - -# Install cert-manager - -`kubectl create namespace eshop` - -Next, use the **`kubectl apply`** command and the **`yaml`** file available online to install the add-on: - -```powershell -kubectl apply --validate=false -f https://github.com/jetstack/cert-manager/releases/download/v1.7.0/cert-manager.yaml -``` - -Now deploy the issuer: +### Install mkcert root ca ```powershell -kubectl apply -f .\selfsigned\issuer.yaml +mkcert -install ``` -Now deploy the certificate: +### Run mkcert ```powershell -kubectl apply -f .\selfsigned\certificate.yaml +mkcert "eshop-st-web" "eshop-st-public-web" "eshop-st-authserver" "eshop-st-identity" "eshop-st-administration" "eshop-st-basket" "eshop-st-catalog" "eshop-st-ordering" "eshop-st-payment" "eshop-st-gateway-web" "eshop-st-gateway-web-public" ``` -Check the certificate: +At the end of the output you will see something like -```powershell -kubectl describe certificate -n=eshop -``` +The certificate is at "./eshop-st-web+10.pem" and the key at "./eshop-st-web+10-key.pem" -Check the secrets: +Copy the cert name and key name below to create tls secret ```powershell -kubectl get secrets -n=eshop +kubectl create namespace eshop +kubectl create secret tls -n eshop eshop-wildcard-tls --cert=./eshop-st-web+10.pem --key=./eshop-st-web+10-key.pem ``` - -You should be seeing `eshop-staging-tls` - -To view information about the Secret, use the **`get secret`** command: - -`kubectl get secret eshop-staging-tls -n cert-manager` diff --git a/etc/k8s/tls-cert/selfsigned/certificate.yaml b/etc/k8s/tls-cert/selfsigned/certificate.yaml deleted file mode 100644 index ec7b9ab2..00000000 --- a/etc/k8s/tls-cert/selfsigned/certificate.yaml +++ /dev/null @@ -1,21 +0,0 @@ -apiVersion: cert-manager.io/v1 -kind: Certificate -metadata: - name: selfsigned-cert - namespace: eshop -spec: - dnsNames: - - "*.eshop-st-web" - - "*.eshop-st-public-web" - - "*.eshop-st-authserver" - - "*.eshop-st-identity" - - "*.eshop-st-administration" - - "*.eshop-st-basket" - - "*.eshop-st-catalog" - - "*.eshop-st-ordering" - - "*.eshop-st-payment" - - "*.eshop-st-gateway-web" - - "*.eshop-st-gateway-web-public" - secretName: eshop-single-tls - issuerRef: - name: eshop-issuer \ No newline at end of file diff --git a/etc/k8s/tls-cert/selfsigned/cluster-issuer.yaml b/etc/k8s/tls-cert/selfsigned/cluster-issuer.yaml deleted file mode 100644 index c69e8a11..00000000 --- a/etc/k8s/tls-cert/selfsigned/cluster-issuer.yaml +++ /dev/null @@ -1,6 +0,0 @@ -apiVersion: cert-manager.io/v1 -kind: ClusterIssuer -metadata: - name: selfsigned-issuer -spec: - selfSigned: {} \ No newline at end of file diff --git a/etc/k8s/tls-cert/selfsigned/issuer.yaml b/etc/k8s/tls-cert/selfsigned/issuer.yaml deleted file mode 100644 index 134fa38c..00000000 --- a/etc/k8s/tls-cert/selfsigned/issuer.yaml +++ /dev/null @@ -1,7 +0,0 @@ -apiVersion: cert-manager.io/v1 -kind: Issuer -metadata: - name: eshop-issuer - # namespace: eshop -spec: - selfSigned: {} \ No newline at end of file diff --git a/etc/k8s/tls-cert/selfsigned/readme.md b/etc/k8s/tls-cert/selfsigned/readme.md deleted file mode 100644 index 198b3bc2..00000000 --- a/etc/k8s/tls-cert/selfsigned/readme.md +++ /dev/null @@ -1,8 +0,0 @@ -`helm install cert-manager jetstack/cert-manager --namespace cert-manager --create-namespace --version v1.4.0 --set installCRDs=true` -`kubectl create ns eshop` -`kubectl apply -f .\selfsigned\issuer.yaml` - - -```powershell -kubectl create secret tls eshop-demo-tls --cert=eshop-st-cert.pem --key=eshop-st-cert.key -n ingress-nginx -``` \ No newline at end of file