kadras-io/package-for-cert-manager-webhook-hetzner

Kubernetes-native package for cert-manager-webhook-hetzner, a webhook that creates the necessary DNS entries in the Hetzner DNS API to solve a DNS01 challenge for a cert-manager Issuer of the ACME type.

โ˜… 0Forks 0MustacheGitHub โ†—Compare
carvelcert-managercertificate-managementhetznerkadraskapp-controllerkubernetessecuritytls

README

cert-manager-webhook-hetzner

Test Workflow Release Workflow The SLSA Level 3 badge The Apache 2.0 license badge Follow us on Bluesky

A Carvel package for cert-manager-webhook-hetzner, a webhook that creates the necessary DNS entries in the Hetzner DNS API to solve a DNS01 challenge for a cert-manager Issuer of the ACME type.

๐Ÿš€ย  Getting Started

Prerequisites

  • Kubernetes 1.34+

  • Carvel kctrl CLI.

  • Carvel kapp-controller deployed in your Kubernetes cluster. You can install it with Carvel kapp (recommended choice) or kubectl.

    kapp deploy -a kapp-controller -y \
      -f https://github.com/carvel-dev/kapp-controller/releases/latest/download/release.yml

Dependencies

cert-manager-webhook-hetzner requires cert-manager. You can install it from the Kadras package repository.

Installation

Add the Kadras package repository to your Kubernetes cluster:

kctrl package repository add -r kadras-packages \
  --url ghcr.io/kadras-io/kadras-packages \
  -n kadras-system --create-namespace
Installation without package repository The recommended way of installing the cert-manager-webhook-hetzner package is via the Kadras package repository. If you prefer not using the repository, you can add the package definition directly using kapp or kubectl.
kubectl create namespace kadras-system
kapp deploy -a cert-manager-webhook-hetzner-package -n kadras-system -y \
  -f https://github.com/kadras-io/package-for-cert-manager-webhook-hetzner/releases/latest/download/metadata.yml \
  -f https://github.com/kadras-io/package-for-cert-manager-webhook-hetzner/releases/latest/download/package.yml

Install the cert-manager-webhook-hetzner package:

kctrl package install -i cert-manager-webhook-hetzner \
  -p cert-manager-webhook-hetzner.packages.kadras.io \
  -v ${VERSION} \
  -n kadras-system

Note You can find the ${VERSION} value by retrieving the list of package versions available in the Kadras package repository installed on your cluster.

kctrl package available list -p cert-manager-webhook-hetzner.packages.kadras.io -n kadras-system

Verify the installed packages and their status:

kctrl package installed list -n kadras-system

๐Ÿ“™ย  Documentation

Documentation, tutorials and examples for this package are available in the docs folder. For documentation specific to cert-manager-webhook-hetzner, check out github.com/hetzner/cert-manager-webhook-hetzner.

๐ŸŽฏย  Configuration

The cert-manager-webhook-hetzner package can be customized via a values.yml file.

webhook:
  replicas: 3

Reference the values.yml file from the kctrl command when installing or upgrading the package.

kctrl package install -i cert-manager-webhook-hetzner \
  -p cert-manager-webhook-hetzner.packages.kadras.io \
  -v ${VERSION} \
  -n kadras-system \
  --values-file values.yml

Values

The cert-manager-webhook-hetzner package has the following configurable properties.

Configurable properties
Config Default Description
webhook.replicas 1 The number of replicas. In order to enable high availability, at least 3 replicas are recommended.
prometheus.enabled true Whether to enable Prometheus annotations for automatic scraping of cert-manager-webhook-hetzner metrics.

๐Ÿ›ก๏ธย  Security

The security process for reporting vulnerabilities is described in SECURITY.md.

๐Ÿ–Š๏ธย  License

This project is licensed under the Apache License 2.0. See LICENSE for more information.

Contributors

ThomasVitale

Issues