Skip to content

Commit 8872f3d

Browse files
author
Darryl Weaver
authored
Merge pull request #142 from weaveworks/release-clusterissuer-chart
Release Clusterissuer chart
2 parents 53475ae + 33e0713 commit 8872f3d

File tree

7 files changed

+183
-0
lines changed

7 files changed

+183
-0
lines changed

charts/clusterissuer/.helmignore

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
# Patterns to ignore when building packages.
2+
# This supports shell glob matching, relative path matching, and
3+
# negation (prefixed with !). Only one pattern per line.
4+
.DS_Store
5+
# Common VCS dirs
6+
.git/
7+
.gitignore
8+
.bzr/
9+
.bzrignore
10+
.hg/
11+
.hgignore
12+
.svn/
13+
# Common backup files
14+
*.swp
15+
*.bak
16+
*.tmp
17+
*.orig
18+
*~
19+
# Various IDEs
20+
.project
21+
.idea/
22+
*.tmproj
23+
.vscode/

charts/clusterissuer/Chart.yaml

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
apiVersion: v2
2+
name: clusterissuer
3+
icon: https://raw.githubusercontent.com/jetstack/cert-manager/master/logo/logo.png
4+
description: A Weaveworks Helm chart for a cert manager cluster issuer using DNS01 validation with route53
5+
type: application
6+
version: 1.0.0
7+
kubeVersion: ">=1.16.0-0"
8+
home: https://github.com/weaveworks/profiles-catalog
9+
sources:
10+
- https://github.com/weaveworks/profiles-catalog
11+
12+
keywords:
13+
- cert-manager
14+
- aws
15+
- route53
16+
- kube-lego
17+
- letsencrypt
18+
- tls
19+
20+
maintainers:
21+
- name: Weaveworks
22+
23+
24+
annotations:
25+
"weave.works/profile": clusterissuer
26+
"weave.works/category": Certificate
27+
"weave.works/layer": layer-2
28+
"weave.works/operator": "false"
29+
"weave.works/links": |
30+
- name: Chart Sources
31+
url: https://github.com/weaveworks/profiles-catalog
32+
"weave.works/profile-ci": |
33+
- "gke"
34+
- "kind"
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
The clusterissuer for route53 domains on aws has been installed
Lines changed: 62 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,62 @@
1+
{{/*
2+
Expand the name of the chart.
3+
*/}}
4+
{{- define "clusterissuer.name" -}}
5+
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
6+
{{- end }}
7+
8+
{{/*
9+
Create a default fully qualified app name.
10+
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
11+
If release name contains chart name it will be used as a full name.
12+
*/}}
13+
{{- define "clusterissuer.fullname" -}}
14+
{{- if .Values.fullnameOverride }}
15+
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
16+
{{- else }}
17+
{{- $name := default .Chart.Name .Values.nameOverride }}
18+
{{- if contains $name .Release.Name }}
19+
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
20+
{{- else }}
21+
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
22+
{{- end }}
23+
{{- end }}
24+
{{- end }}
25+
26+
{{/*
27+
Create chart name and version as used by the chart label.
28+
*/}}
29+
{{- define "clusterissuer.chart" -}}
30+
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
31+
{{- end }}
32+
33+
{{/*
34+
Common labels
35+
*/}}
36+
{{- define "clusterissuer.labels" -}}
37+
helm.sh/chart: {{ include "clusterissuer.chart" . }}
38+
{{ include "clusterissuer.selectorLabels" . }}
39+
{{- if .Chart.AppVersion }}
40+
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
41+
{{- end }}
42+
app.kubernetes.io/managed-by: {{ .Release.Service }}
43+
{{- end }}
44+
45+
{{/*
46+
Selector labels
47+
*/}}
48+
{{- define "clusterissuer.selectorLabels" -}}
49+
app.kubernetes.io/name: {{ include "clusterissuer.name" . }}
50+
app.kubernetes.io/instance: {{ .Release.Name }}
51+
{{- end }}
52+
53+
{{/*
54+
Create the name of the service account to use
55+
*/}}
56+
{{- define "clusterissuer.serviceAccountName" -}}
57+
{{- if .Values.serviceAccount.create }}
58+
{{- default (include "clusterissuer.fullname" .) .Values.serviceAccount.name }}
59+
{{- else }}
60+
{{- default "default" .Values.serviceAccount.name }}
61+
{{- end }}
62+
{{- end }}
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
{{- if .Values.externalSecret.create }}
2+
apiVersion: external-secrets.io/v1beta1
3+
kind: ExternalSecret
4+
metadata:
5+
creationTimestamp: null
6+
name: clusterissuer-static-secret
7+
namespace: cert-manager
8+
spec:
9+
dataFrom:
10+
- extract:
11+
key: {{ .Values.externalSecret.secretManager.path }}
12+
refreshInterval: 1h0m0s
13+
secretStoreRef:
14+
kind: ClusterSecretStore
15+
name: {{ .Values.externalSecret.clusterSecretStore.name }}
16+
target:
17+
creationPolicy: Owner
18+
name: {{ .Values.externalSecret.secretName }}
19+
status:
20+
refreshTime: null
21+
{{- end }}
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
apiVersion: cert-manager.io/v1
2+
kind: ClusterIssuer
3+
metadata:
4+
name: letsencrypt
5+
spec:
6+
acme:
7+
server: https://acme-v02.api.letsencrypt.org/directory
8+
email: {{ .Values.clusterIssuerEmail }}
9+
privateKeySecretRef:
10+
name: letsencrypt
11+
solvers:
12+
- dns01:
13+
route53:
14+
region: {{ .Values.region }}
15+
{{- if .Values.accessKeyId.enabled }}
16+
accessKeyID: {{ .Values.accessKeyId.value }}
17+
{{- end }}
18+
{{- if .Values.externalSecret.create }}
19+
secretAccessKeySecretRef:
20+
name: {{ .Values.externalSecret.secretName }}
21+
key: secret-access-key
22+
{{- else }}
23+
secretAccessKeySecretRef:
24+
name: ""
25+
{{- end }}
26+
selector:
27+
dnsZones:
28+
- {{ .Values.dnsZone }}
29+

charts/clusterissuer/values.yaml

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
clusterIssuerEmail: [email protected]
2+
dnsZone: cx.weave.works
3+
accessKeyId:
4+
enabled: false
5+
value: AWS_ACCESS_KEY
6+
region: us-west-1
7+
externalSecret:
8+
create: false
9+
secretName: aws-route53-creds
10+
clusterSecretStore:
11+
name: aws-secretmanager
12+
secretManager:
13+
path: demo/clusterissuer/aws-route53-creds

0 commit comments

Comments
 (0)