
Let's Encrypt is an automated, open certificate authority that offers free TLS/SSL certificates for public benefit. The service is provided by the Internet Security Research Group (ISRG). You can generate a wildcard SSL certificate to secure unlimited subdomains that belong to the same domain name. For example, a wildcard SSL certificate generated for example.com can secure www.example.com, app.example.com, test.example.com, and so on.
This article demonstrates the steps to install the required plugins, generate a wildcard SSL certificate and secure a sample deployment using the Nginx Ingress controller and the generated certificate.
Before you begin, you should:
The ExternalDNS add-on allows the Kubernetes cluster to manage the Vultr DNS zones and synchronize the exposed services/ingresses with the DNS records. You need to install this add-on as Let's Encrypt requires you to prove the full ownership of the domain name. In this case, the ACME client, cert-manager verifies the ownership by adding a special DNS record in the domain name.
Create a new manifest file named 1-dns.yaml.
Add the following contents to the file.
The above manifest deploys the ExternalDNS add-on on the Kubernetes cluster. Be sure to populate the VULTR_API_KEY value with your API key. You can locate the API key by navigating to the Vultr Console > Account > API.
Apply the manifest file.
The nginx-ingress controller is a Kubernetes resource that provisions a load balancer and configures it to expose the ingress resources outside the cluster. It is a cluster-wise resource that you can use to expose multiple services using ingress resources.
Install the nginx-ingress controller.
Verify the installation.
The cert-manager plugin adds the certificates and certificate issuers as resource types in the Kubernetes cluster. It simplifies the process of obtaining, renewing, and using the certificates.
Install the cert-manager plugin.
Verify the installation.
The Vultr Webhook allows using the ACME DNS01 solver by Vultr with the cert-manager plugin to issue the Let's Encrypt certificates. You must perform this step after installing the cert-manager plugin on the cluster.
Clone the GitHub repository.
Create a secret resource.
The above command creates a secret resource for defining the Vultr credentials. Replace <VULTR API KEY> with your API key.
Install the webhook.
Create a new manifest file named 2-webhook.yaml.
Add the following contents to the file.
The above manifest creates the ClusterIssuer resource for issuing Let's Encrypt certificates. It also defines the necessary role bindings for the webhook to function properly. Populate the spec.acme.email field with your email address.
Apply the manifest file.
Verify the installation.
This section demonstrates the steps to create a Certificate resource which requests the Let's Encrypt CA to issue a wildcard SSL certificate for *.example.com and store it in a secret resource named wildcard-tls.
Create a new manifest file named 3-certificate.yaml.
Add the following contents to the file.
The above manifest creates a Certificate resource for *.example.com that you use in the later steps to secure a sample Nginx deployment.
Apply the manifest file.
You create a sample Deployment resource in this section using the official Nginx image. You can swap this step with the deployment of your existing web application and change the name of the service in the next section.
Create a new manifest file named 4-nginx.yaml.
Add the following contents to the file.
The above manifest creates a Deployment resource to run a sample Nginx container and a Service resource to expose the connections inside the cluster.
Apply the manifest file.
In the previous steps, you installed the nginx-ingress controller to expose Kubernetes services outside the cluster. In this section, you create an ingress resource to expose the nginx-svc service outside the cluster bound with the test.example.com subdomain and secure it with the wildcard SSL certificate.
Create a new manifest file named 5-ingress.yaml.
Add the following contents to the file.
The above manifest creates an Ingress resource to expose the nginx-svc outside the cluster and secure it with the wildcard certificate stored in the wildcard-tls secret resource.
Apply the manifest file.
You can verify the deployment by opening test.example.com on your web browser a few minutes after applying the manifest file.
This article demonstrated the steps to install the required plugins, generate a wildcard SSL certificate and secure a sample deployment using the Nginx Ingress controller and the generated certificate. You can follow these steps to generate a wildcard SSL certificate for your domain name and secure your Kubernetes deployments.
0 Comments
Be the first to comment and share your perspective with the community.