fix Certificate SANs

This commit is contained in:
kkb0318
2024-05-15 00:28:54 +09:00
parent 9f90f45b68
commit 0e56e4ffba
2 changed files with 7 additions and 6 deletions
+6 -5
View File
@@ -5,7 +5,6 @@ import (
"crypto/rsa"
"crypto/x509"
"crypto/x509/pkix"
"encoding/base64"
"encoding/pem"
"math/big"
"time"
@@ -18,10 +17,6 @@ type TlsCredential struct {
certificate []byte
}
func (t TlsCredential) CaBundle() string {
return base64.StdEncoding.EncodeToString(t.certificate)
}
func (t TlsCredential) Certificate() []byte {
return t.certificate
}
@@ -53,6 +48,12 @@ func CreateTlsCredential(serviceNamespacedName types.NamespacedName) (TlsCredent
IsCA: true,
}
// Add SANs to the certificate template
template.DNSNames = []string{
serviceNamespacedName.Name + "." + serviceNamespacedName.Namespace + ".svc",
serviceNamespacedName.Name + "." + serviceNamespacedName.Namespace + ".svc.cluster.local",
}
// Create the certificate
certBytes, err := x509.CreateCertificate(rand.Reader, &template, &template, &privateKey.PublicKey, privateKey)
if err != nil {
+1 -1
View File
@@ -69,7 +69,7 @@ func myCertificate(base *baseManifestFactory) ([]client.Object, error) {
},
}
mutate := base.mutatingWebhookConfiguration()
mutate.Webhooks[0].ClientConfig.CABundle = []byte(tlsCredential.CaBundle())
mutate.Webhooks[0].ClientConfig.CABundle = tlsCredential.Certificate()
resources = append(resources,
secret,
deploy,