tls-secret.yaml 2.6 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253
  1. {{- if (include "zookeeper.client.createTlsSecret" .) }}
  2. ---
  3. {{- $ca := genCA "zookeeper-client-ca" 365 }}
  4. {{- $releaseNamespace := .Release.Namespace }}
  5. {{- $clusterDomain := .Values.clusterDomain }}
  6. {{- $fullname := include "common.names.fullname" . }}
  7. {{- $serviceName := include "common.names.fullname" . }}
  8. {{- $altNames := list (printf "*.%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) $fullname }}
  9. {{- $crt := genSignedCert $fullname nil $altNames 365 $ca }}
  10. apiVersion: v1
  11. kind: Secret
  12. metadata:
  13. name: {{ include "common.names.fullname" . }}-client-crt
  14. labels: {{- include "common.labels.standard" . | nindent 4 }}
  15. {{- if .Values.commonLabels }}
  16. {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
  17. {{- end }}
  18. {{- if .Values.commonAnnotations }}
  19. annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
  20. {{- end }}
  21. type: kubernetes.io/tls
  22. data:
  23. ca.crt: {{ $ca.Cert | b64enc | quote }}
  24. tls.crt: {{ $crt.Cert | b64enc | quote }}
  25. tls.key: {{ $crt.Key | b64enc | quote }}
  26. {{- end }}
  27. {{- if (include "zookeeper.quorum.createTlsSecret" .) }}
  28. ---
  29. {{- $ca := genCA "zookeeper-quorum-ca" 365 }}
  30. {{- $releaseNamespace := .Release.Namespace }}
  31. {{- $clusterDomain := .Values.clusterDomain }}
  32. {{- $fullname := include "common.names.fullname" . }}
  33. {{- $serviceName := include "common.names.fullname" . }}
  34. {{- $headlessServiceName := printf "%s-headless" (include "common.names.fullname" .) }}
  35. {{- $altNames := list (printf "*.%s.%s.svc.%s" $headlessServiceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc.%s" $headlessServiceName $releaseNamespace $clusterDomain) (printf "*.%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc.%s" $serviceName $releaseNamespace $clusterDomain) $fullname }}
  36. {{- $crt := genSignedCert $fullname nil $altNames 365 $ca }}
  37. apiVersion: v1
  38. kind: Secret
  39. metadata:
  40. name: {{ include "common.names.fullname" . }}-quorum-crt
  41. labels: {{- include "common.labels.standard" . | nindent 4 }}
  42. {{- if .Values.commonLabels }}
  43. {{- include "common.tplvalues.render" ( dict "value" .Values.commonLabels "context" $ ) | nindent 4 }}
  44. {{- end }}
  45. {{- if .Values.commonAnnotations }}
  46. annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
  47. {{- end }}
  48. type: kubernetes.io/tls
  49. data:
  50. ca.crt: {{ $ca.Cert | b64enc | quote }}
  51. tls.crt: {{ $crt.Cert | b64enc | quote }}
  52. tls.key: {{ $crt.Key | b64enc | quote }}
  53. {{- end }}