How do you manage the distribution of internal TLS network certificates? I’m using cert-manager to generate them, but the root self-signed certificate expires monthly which makes distribution to devices outside of K8s a challenge. It’s a PITA to keep doing this for the tablet, laptop and phones. I can bump the root cert to a year, but I’m concerned that the date will sneak up on me. Are there any automated solutions?

  • johntash@eviltoast.org
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 hours ago

    If the operator doesn’t allow it for some reason, uninstall it and try with the helm chart instead?

    Or is there a reason to use the operator?