Live data from Hacker News

Simplify Lets Encrypt Certificates Management for Kubernetes

github.com

1–10 of 18 posts

Re: Simplify Lets Encrypt Certificates Management for Kubernetes

#2
I've been using this project on GKE for ~2 weeks now in combination with the nginx ingress controller. I have it configured to use the DNS challenge to get new certs so I don't have to expose an extra port as well.

It feels liberating to just get an SSL cert for any subdomain I need and have the whole process abstracted from me.

Re: Simplify Lets Encrypt Certificates Management for Kubernetes

#3
post #2

I've been using this project on GKE for ~2 weeks now in combination with the nginx ingress controller. I have it configured to use the DNS challenge to get new certs so I don't have to expose an extra port as well. It feels liberating to just get an SSL cert for any subdomain I need and have the whole process abstracted from me.

Sicne a few days ago, ingress objects are now supported directly with the correct annotations. See https://github.com/PalmStoneGames/kube-cert-manager/blob/mas...

Re: Simplify Lets Encrypt Certificates Management for Kubernetes

#5
post #4

I'm curious what advantages and tradeoffs it has over the project that it is based upon [1] for a person choosing between them. [1]: https://github.com/kelseyhightower/kube-cert-manager

Largely, https://github.com/kelseyhightower/kube-cert-manager is incomplete

* it does not support subdomains (only root domains)

* it only supports googlecloud as dns provider

* Bugs and PRs remain unanswered/unmerged

Meanwhile the linked project supports http, SNI and DNS challenges, with around 20 or so DNS providers available. It also supports managing certs for ingress objects directly.

Re: Simplify Lets Encrypt Certificates Management for Kubernetes

#6
post #5
post #4

I'm curious what advantages and tradeoffs it has over the project that it is based upon [1] for a person choosing between them. [1]: https://github.com/kelseyhightower/kube-cert-manager

Largely, https://github.com/kelseyhightower/kube-cert-manager is incomplete * it does not support subdomains (only root domains) * it only supports googlecloud as dns provider * Bugs and PRs remain unanswered/unmerged Meanwhile the linked project supports http, SNI and DNS challenges, with around 20 or so DNS providers available. It also supports managing certs for ingress objects directly.

Does it support multiple SANs on a single cert? I want to streamline things like vanity domain redirections, where every domain I add requires me to refresh the cert.

Re: Simplify Lets Encrypt Certificates Management for Kubernetes

#7
post #5

Earlier quoted context omitted.

Largely, https://github.com/kelseyhightower/kube-cert-manager is incomplete * it does not support subdomains (only root domains) * it only supports googlecloud as dns provider * Bugs and PRs remain unanswered/unmerged Meanwhile the linked project supports http, SNI and DNS challenges, with around 20 or so DNS providers available. It also supports managing certs for ingress objects directly.

Does it support multiple SANs on a single cert? I want to streamline things like vanity domain redirections, where every domain I add requires me to refresh the cert.

Unfortunately, not currently, no :< It's trivial to get seperate certs, but getting them all on a single cert is not in yet.

Re: Simplify Lets Encrypt Certificates Management for Kubernetes

#8
I thought I wanted this for a long time, but `kube-lego` gets me very similar results... without needing to inject credentials for my DNS provider to my cluster.

I'm curious if others have thoughts on this vs kube-lego. (I would agree that I like the approach of this project quite a bit more than kelseyhightower's. This feels more complete, works with far more providers, etc)

Re: Simplify Lets Encrypt Certificates Management for Kubernetes

#10
post #4

I'm curious what advantages and tradeoffs it has over the project that it is based upon [1] for a person choosing between them. [1]: https://github.com/kelseyhightower/kube-cert-manager

I haven't used this yet but will say that lego (which this uses) is a joy to use.
Post reply on HN