diff --git a/internal/selfhosted/webhook/certificate.go b/internal/selfhosted/webhook/certificate.go index bc08fa1..d8b597c 100644 --- a/internal/selfhosted/webhook/certificate.go +++ b/internal/selfhosted/webhook/certificate.go @@ -5,7 +5,6 @@ import ( "crypto/rsa" "crypto/x509" "crypto/x509/pkix" - "encoding/base64" "encoding/pem" "math/big" "time" @@ -18,10 +17,6 @@ type TlsCredential struct { certificate []byte } -func (t TlsCredential) CaBundle() string { - return base64.StdEncoding.EncodeToString(t.certificate) -} - func (t TlsCredential) Certificate() []byte { return t.certificate } @@ -53,6 +48,12 @@ func CreateTlsCredential(serviceNamespacedName types.NamespacedName) (TlsCredent IsCA: true, } + // Add SANs to the certificate template + template.DNSNames = []string{ + serviceNamespacedName.Name + "." + serviceNamespacedName.Namespace + ".svc", + serviceNamespacedName.Name + "." + serviceNamespacedName.Namespace + ".svc.cluster.local", + } + // Create the certificate certBytes, err := x509.CreateCertificate(rand.Reader, &template, &template, &privateKey.PublicKey, privateKey) if err != nil { diff --git a/internal/selfhosted/webhook/webhook.go b/internal/selfhosted/webhook/webhook.go index 8ec6e1a..a6ca509 100644 --- a/internal/selfhosted/webhook/webhook.go +++ b/internal/selfhosted/webhook/webhook.go @@ -69,7 +69,7 @@ func myCertificate(base *baseManifestFactory) ([]client.Object, error) { }, } mutate := base.mutatingWebhookConfiguration() - mutate.Webhooks[0].ClientConfig.CABundle = []byte(tlsCredential.CaBundle()) + mutate.Webhooks[0].ClientConfig.CABundle = tlsCredential.Certificate() resources = append(resources, secret, deploy,