mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
fix Certificate SANs
This commit is contained in:
@@ -5,7 +5,6 @@ import (
|
||||
"crypto/rsa"
|
||||
"crypto/x509"
|
||||
"crypto/x509/pkix"
|
||||
"encoding/base64"
|
||||
"encoding/pem"
|
||||
"math/big"
|
||||
"time"
|
||||
@@ -18,10 +17,6 @@ type TlsCredential struct {
|
||||
certificate []byte
|
||||
}
|
||||
|
||||
func (t TlsCredential) CaBundle() string {
|
||||
return base64.StdEncoding.EncodeToString(t.certificate)
|
||||
}
|
||||
|
||||
func (t TlsCredential) Certificate() []byte {
|
||||
return t.certificate
|
||||
}
|
||||
@@ -53,6 +48,12 @@ func CreateTlsCredential(serviceNamespacedName types.NamespacedName) (TlsCredent
|
||||
IsCA: true,
|
||||
}
|
||||
|
||||
// Add SANs to the certificate template
|
||||
template.DNSNames = []string{
|
||||
serviceNamespacedName.Name + "." + serviceNamespacedName.Namespace + ".svc",
|
||||
serviceNamespacedName.Name + "." + serviceNamespacedName.Namespace + ".svc.cluster.local",
|
||||
}
|
||||
|
||||
// Create the certificate
|
||||
certBytes, err := x509.CreateCertificate(rand.Reader, &template, &template, &privateKey.PublicKey, privateKey)
|
||||
if err != nil {
|
||||
|
||||
@@ -69,7 +69,7 @@ func myCertificate(base *baseManifestFactory) ([]client.Object, error) {
|
||||
},
|
||||
}
|
||||
mutate := base.mutatingWebhookConfiguration()
|
||||
mutate.Webhooks[0].ClientConfig.CABundle = []byte(tlsCredential.CaBundle())
|
||||
mutate.Webhooks[0].ClientConfig.CABundle = tlsCredential.Certificate()
|
||||
resources = append(resources,
|
||||
secret,
|
||||
deploy,
|
||||
|
||||
Reference in New Issue
Block a user