Sign inSign up

dsoderlund/proxmox_certupdater

By dsoderlund

•Updated about 1 month ago

Handy code to upload Lets Encrypt TLS certificates to Proxmox VE nodes for serving and use.

Image
0

40

dsoderlund/proxmox_certupdater repository overview

Created by Jeffery Forman. https://github.com/jforman/proxmox_certupdater⁠

Cloned, patched, and built by me, your milage may vary. https://blog.dsoderlund.consulting/certs-for-your-home-lab#proxmox-web-api⁠

You can use the UI to generate a token, or use this script to get a minimal role, a new user, and a token for that user that you can use out of the box.

pveum role add CertUpdaterRole -privs "Sys.Modify"
pveum user add certupdater@pve --comment "Automated TLS Certificate Updater"
pveum acl modify /nodes --user certupdater@pve --role CertUpdaterRole
pveum user token add certupdater@pve certtoken --privsep 0

Then put the token into a file named `proxmox-cerupdater-apitoken.txt like so:

[default]
user = certupdater@pve
id = certtoken
secret = <your-token-guid-here>

Which you can input as a secret to use in your cluster (and namespace) of choice: kubectl create secret generic proxmox-certupdater-api-key --from-file proxmox-certupdater-apitoken.txt

And then it will work as the example layed out in the github repo. In this example I want to set the certificate for proxmox running on a node named ds2 on the URL https://proxmox.office.dsoderlund.consulting:8006/

apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
  name: proxmox-tls
  namespace: office
spec:
  secretName: proxmox-tls
  dnsNames:
  - "proxmox.office.dsoderlund.consulting"
  duration: 720h0m0s # 30d
  renewBefore: 240h0m0s # 10d
  privateKey:
    algorithm: RSA
    encoding: PKCS1
    size: 2048
  usages:
    - "digital signature"
    - "key encipherment"
  issuerRef:
    name: letsencrypt-prod
    kind: ClusterIssuer
---
apiVersion: batch/v1
kind: Job
metadata:
  name: certupdater-proxmox
  namespace: office
spec:
  template:
    metadata:
      labels:
        app: certupdater-proxmox      
    spec:
      restartPolicy: Never
      containers:
      - name: certupdater-proxmox
        image: docker.io/dsoderlund/proxmox_certupdater:latest
        imagePullPolicy: Always
        command:
        - ./certupdater.py
        args:
        - --auth=/proxmox-creds/proxmox-certupdater-apitoken.txt
        - --cert_dir=/certs
        - --destination=proxmox.office.dsoderlund.consulting
        - --node=ds2
        volumeMounts:
        - name: proxmox-creds
          mountPath: "/proxmox-creds"
          readOnly: true
        - name: proxmox-certs
          mountPath: "/certs"
          readOnly: true            
      volumes:
      - name: proxmox-creds
        secret:
          secretName: proxmox-certupdater-api-key
      - name: proxmox-certs
        secret:
          secretName: proxmox-tls

Tag summary

Content type

Image

Digest

sha256:f04a8b5ff…

Size

21.5 MB

Last updated

about 1 month ago

docker pull dsoderlund/proxmox_certupdater