A Carvel package for cert-manager-webhook-hetzner, a webhook that creates the necessary DNS entries in the Hetzner DNS API to solve a DNS01 challenge for a cert-manager Issuer of the ACME type.
-
Kubernetes 1.34+
-
Carvel
kctrlCLI. -
Carvel kapp-controller deployed in your Kubernetes cluster. You can install it with Carvel
kapp(recommended choice) orkubectl.kapp deploy -a kapp-controller -y \ -f https://github.com/carvel-dev/kapp-controller/releases/latest/download/release.yml
cert-manager-webhook-hetzner requires cert-manager. You can install it from the Kadras package repository.
Add the Kadras package repository to your Kubernetes cluster:
kctrl package repository add -r kadras-packages \
--url ghcr.io/kadras-io/kadras-packages \
-n kadras-system --create-namespaceInstallation without package repository
The recommended way of installing the cert-manager-webhook-hetzner package is via the Kadras package repository. If you prefer not using the repository, you can add the package definition directly usingkapp or kubectl.
kubectl create namespace kadras-system
kapp deploy -a cert-manager-webhook-hetzner-package -n kadras-system -y \
-f https://github.com/kadras-io/package-for-cert-manager-webhook-hetzner/releases/latest/download/metadata.yml \
-f https://github.com/kadras-io/package-for-cert-manager-webhook-hetzner/releases/latest/download/package.ymlInstall the cert-manager-webhook-hetzner package:
kctrl package install -i cert-manager-webhook-hetzner \
-p cert-manager-webhook-hetzner.packages.kadras.io \
-v ${VERSION} \
-n kadras-systemNote You can find the
${VERSION}value by retrieving the list of package versions available in the Kadras package repository installed on your cluster.kctrl package available list -p cert-manager-webhook-hetzner.packages.kadras.io -n kadras-system
Verify the installed packages and their status:
kctrl package installed list -n kadras-systemDocumentation, tutorials and examples for this package are available in the docs folder. For documentation specific to cert-manager-webhook-hetzner, check out github.com/hetzner/cert-manager-webhook-hetzner.
The cert-manager-webhook-hetzner package can be customized via a values.yml file.
webhook:
replicas: 3Reference the values.yml file from the kctrl command when installing or upgrading the package.
kctrl package install -i cert-manager-webhook-hetzner \
-p cert-manager-webhook-hetzner.packages.kadras.io \
-v ${VERSION} \
-n kadras-system \
--values-file values.ymlThe cert-manager-webhook-hetzner package has the following configurable properties.
Configurable properties
| Config | Default | Description |
|---|---|---|
webhook.replicas |
1 |
The number of replicas. In order to enable high availability, at least 3 replicas are recommended. |
prometheus.enabled |
true |
Whether to enable Prometheus annotations for automatic scraping of cert-manager-webhook-hetzner metrics. |
The security process for reporting vulnerabilities is described in SECURITY.md.
This project is licensed under the Apache License 2.0. See LICENSE for more information.