mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-24 21:26:28 +00:00
rustfs#1916 Allow existing secrets to be used for tls certs in ingress (#1918)
Signed-off-by: mkrueger92 <7305571+mkrueger92@users.noreply.github.com> Co-authored-by: houseme <housemecn@gmail.com>
This commit is contained in:
@@ -31,7 +31,11 @@ spec:
|
|||||||
{{- range .Values.ingress.hosts }}
|
{{- range .Values.ingress.hosts }}
|
||||||
- {{ .host | quote }}
|
- {{ .host | quote }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
{{- if .Values.ingress.tls.existingSecret.enabled }}
|
||||||
|
secretName: {{ required "ingress.tls.existingSecret.name must be set when ingress.tls.existingSecret.enabled is true" .Values.ingress.tls.existingSecret.name }}
|
||||||
|
{{- else }}
|
||||||
secretName: {{ include "rustfs.fullname" $ }}-tls
|
secretName: {{ include "rustfs.fullname" $ }}-tls
|
||||||
|
{{- end }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
rules:
|
rules:
|
||||||
{{- range .Values.ingress.hosts }}
|
{{- range .Values.ingress.hosts }}
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{{- if and .Values.ingress.tls.enabled (not .Values.ingress.tls.certManager.enabled) -}}
|
{{- if and .Values.ingress.tls.enabled (not .Values.ingress.tls.certManager.enabled) (not .Values.ingress.tls.existingSecret.enabled) -}}
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Secret
|
kind: Secret
|
||||||
metadata:
|
metadata:
|
||||||
@@ -8,6 +8,6 @@ metadata:
|
|||||||
{{- toYaml .Values.commonLabels | nindent 4 }}
|
{{- toYaml .Values.commonLabels | nindent 4 }}
|
||||||
type: kubernetes.io/tls
|
type: kubernetes.io/tls
|
||||||
data:
|
data:
|
||||||
tls.crt : {{ .Values.ingress.tls.crt | b64enc | quote }}
|
tls.crt: {{ .Values.ingress.tls.crt | b64enc | quote }}
|
||||||
tls.key : {{ .Values.ingress.tls.key | b64enc | quote }}
|
tls.key: {{ .Values.ingress.tls.key | b64enc | quote }}
|
||||||
{{- end }}
|
{{- end }}
|
||||||
|
|||||||
+13
-1
@@ -144,9 +144,21 @@ ingress:
|
|||||||
pathType: Prefix
|
pathType: Prefix
|
||||||
tls:
|
tls:
|
||||||
enabled: false # Enable tls and access rustfs via https.
|
enabled: false # Enable tls and access rustfs via https.
|
||||||
|
|
||||||
certManager:
|
certManager:
|
||||||
enabled: false # Enable certmanager to generate certificate for rustfs, default false.
|
enabled: false # Enable certmanager to generate certificate for rustfs, default false.
|
||||||
secretName: secret-tls
|
|
||||||
|
existingSecret:
|
||||||
|
# To use an existing secret for tls certificates in the ingress enable this,
|
||||||
|
# set the name of the existing secret and make sure that the secret contains
|
||||||
|
# values for the keys "crt" and "key".
|
||||||
|
enabled: false
|
||||||
|
name: ""
|
||||||
|
|
||||||
|
# If the certmanager is not used and no existing secret is used to provide a tls certificate,
|
||||||
|
# then this certificate can be configured here. A secret will be created and used.
|
||||||
|
# Note: The following input will be base64 encoded during secret creation. There is no need
|
||||||
|
# to provide it base64 encoded here already.
|
||||||
crt: tls.crt
|
crt: tls.crt
|
||||||
key: tls.key
|
key: tls.key
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user