rustfs#1916 Allow existing secrets to be used for tls certs in ingress (#1918)

Signed-off-by: mkrueger92 <7305571+mkrueger92@users.noreply.github.com>
Co-authored-by: houseme <housemecn@gmail.com>
This commit is contained in:
mkrueger92
2026-02-24 13:34:08 +01:00
committed by GitHub
parent c692777ead
commit 3b024a9dc5
3 changed files with 20 additions and 4 deletions
+4
View File
@@ -31,7 +31,11 @@ spec:
{{- range .Values.ingress.hosts }}
- {{ .host | quote }}
{{- end }}
{{- if .Values.ingress.tls.existingSecret.enabled }}
secretName: {{ required "ingress.tls.existingSecret.name must be set when ingress.tls.existingSecret.enabled is true" .Values.ingress.tls.existingSecret.name }}
{{- else }}
secretName: {{ include "rustfs.fullname" $ }}-tls
{{- end }}
{{- end }}
rules:
{{- range .Values.ingress.hosts }}
+3 -3
View File
@@ -1,4 +1,4 @@
{{- if and .Values.ingress.tls.enabled (not .Values.ingress.tls.certManager.enabled) -}}
{{- if and .Values.ingress.tls.enabled (not .Values.ingress.tls.certManager.enabled) (not .Values.ingress.tls.existingSecret.enabled) -}}
apiVersion: v1
kind: Secret
metadata:
@@ -8,6 +8,6 @@ metadata:
{{- toYaml .Values.commonLabels | nindent 4 }}
type: kubernetes.io/tls
data:
tls.crt : {{ .Values.ingress.tls.crt | b64enc | quote }}
tls.key : {{ .Values.ingress.tls.key | b64enc | quote }}
tls.crt: {{ .Values.ingress.tls.crt | b64enc | quote }}
tls.key: {{ .Values.ingress.tls.key | b64enc | quote }}
{{- end }}
+13 -1
View File
@@ -144,9 +144,21 @@ ingress:
pathType: Prefix
tls:
enabled: false # Enable tls and access rustfs via https.
certManager:
enabled: false # Enable certmanager to generate certificate for rustfs, default false.
secretName: secret-tls
existingSecret:
# To use an existing secret for tls certificates in the ingress enable this,
# set the name of the existing secret and make sure that the secret contains
# values for the keys "crt" and "key".
enabled: false
name: ""
# If the certmanager is not used and no existing secret is used to provide a tls certificate,
# then this certificate can be configured here. A secret will be created and used.
# Note: The following input will be base64 encoded during secret creation. There is no need
# to provide it base64 encoded here already.
crt: tls.crt
key: tls.key