Skip to content
Snippets Groups Projects
Unverified Commit ee2193d4 authored by ERIK's avatar ERIK Committed by GitHub
Browse files

Add dns configuration for cert manager (#9673)


Signed-off-by: default avatarbo.jiang <bo.jiang@daocloud.io>

Signed-off-by: default avatarbo.jiang <bo.jiang@daocloud.io>
parent eb561304
No related branches found
No related tags found
No related merge requests found
...@@ -161,6 +161,12 @@ cert_manager_enabled: false ...@@ -161,6 +161,12 @@ cert_manager_enabled: false
# -----END CERTIFICATE----- # -----END CERTIFICATE-----
# cert_manager_leader_election_namespace: kube-system # cert_manager_leader_election_namespace: kube-system
# cert_manager_dns_policy: "ClusterFirst"
# cert_manager_dns_config:
# nameservers:
# - "1.1.1.1"
# - "8.8.8.8"
# MetalLB deployment # MetalLB deployment
metallb_enabled: false metallb_enabled: false
metallb_speaker_enabled: "{{ metallb_enabled }}" metallb_speaker_enabled: "{{ metallb_enabled }}"
......
...@@ -4,6 +4,9 @@ cert_manager_user: 1001 ...@@ -4,6 +4,9 @@ cert_manager_user: 1001
cert_manager_tolerations: [] cert_manager_tolerations: []
cert_manager_affinity: {} cert_manager_affinity: {}
cert_manager_nodeselector: {} cert_manager_nodeselector: {}
cert_manager_dns_policy: "ClusterFirst"
cert_manager_dns_config: {}
## Change leader election namespace when deploying on GKE Autopilot that forbid the changes on kube-system namespace. ## Change leader election namespace when deploying on GKE Autopilot that forbid the changes on kube-system namespace.
## See https://github.com/jetstack/cert-manager/issues/3717 ## See https://github.com/jetstack/cert-manager/issues/3717
......
...@@ -976,6 +976,13 @@ spec: ...@@ -976,6 +976,13 @@ spec:
affinity: affinity:
{{ cert_manager_affinity | to_nice_yaml | indent(width=8) }} {{ cert_manager_affinity | to_nice_yaml | indent(width=8) }}
{% endif %} {% endif %}
{% if cert_manager_dns_policy %}
dnsPolicy: {{ cert_manager_dns_policy }}
{% endif %}
{% if cert_manager_dns_config %}
dnsConfig:
{{ cert_manager_dns_config | to_nice_yaml | indent(width=8) }}
{% endif %}
{% if cert_manager_trusted_internal_ca is defined %} {% if cert_manager_trusted_internal_ca is defined %}
volumeMounts: volumeMounts:
- mountPath: /etc/ssl/certs/internal-ca.pem - mountPath: /etc/ssl/certs/internal-ca.pem
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment