Peter Kurfer
647f602c79
- added Core CRD to manage DB migrations & configuration, PostgREST and GoTrue (auth) - added APIGateway CRD to manage Envoy proxy - added Dashboard CRD to manage (so far) pg-meta and (soon) studio deployments - implemented basic Envoy control plane based on K8s watcher
35 lines
1.3 KiB
YAML
35 lines
1.3 KiB
YAML
# The following manifests contain a self-signed issuer CR and a certificate CR.
|
|
# More document can be found at https://docs.cert-manager.io
|
|
# WARNING: Targets CertManager v1.0. Check https://cert-manager.io/docs/installation/upgrading/ for breaking changes.
|
|
apiVersion: cert-manager.io/v1
|
|
kind: Issuer
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: supabase-operator
|
|
app.kubernetes.io/managed-by: kustomize
|
|
name: selfsigned-issuer
|
|
namespace: supabase-system
|
|
spec:
|
|
selfSigned: {}
|
|
---
|
|
apiVersion: cert-manager.io/v1
|
|
kind: Certificate
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/name: certificate
|
|
app.kubernetes.io/instance: serving-cert
|
|
app.kubernetes.io/component: certificate
|
|
app.kubernetes.io/created-by: supabase-operator
|
|
app.kubernetes.io/part-of: supabase-operator
|
|
app.kubernetes.io/managed-by: kustomize
|
|
name: serving-cert # this name should match the one appeared in kustomizeconfig.yaml
|
|
namespace: supabase-system
|
|
spec:
|
|
# SERVICE_NAME and SERVICE_NAMESPACE will be substituted by kustomize
|
|
dnsNames:
|
|
- SERVICE_NAME.SERVICE_NAMESPACE.svc
|
|
- SERVICE_NAME.SERVICE_NAMESPACE.svc.cluster.local
|
|
issuerRef:
|
|
kind: Issuer
|
|
name: selfsigned-issuer
|
|
secretName: webhook-server-cert # this secret will not be prefixed, since it's not managed by kustomize
|