Handy code to upload Lets Encrypt TLS certificates to Proxmox VE nodes for serving and use.
40
Created by Jeffery Forman. https://github.com/jforman/proxmox_certupdater
Cloned, patched, and built by me, your milage may vary. https://blog.dsoderlund.consulting/certs-for-your-home-lab#proxmox-web-api
You can use the UI to generate a token, or use this script to get a minimal role, a new user, and a token for that user that you can use out of the box.
pveum role add CertUpdaterRole -privs "Sys.Modify"
pveum user add certupdater@pve --comment "Automated TLS Certificate Updater"
pveum acl modify /nodes --user certupdater@pve --role CertUpdaterRole
pveum user token add certupdater@pve certtoken --privsep 0
Then put the token into a file named `proxmox-cerupdater-apitoken.txt like so:
[default]
user = certupdater@pve
id = certtoken
secret = <your-token-guid-here>
Which you can input as a secret to use in your cluster (and namespace) of choice:
kubectl create secret generic proxmox-certupdater-api-key --from-file proxmox-certupdater-apitoken.txt
And then it will work as the example layed out in the github repo.
In this example I want to set the certificate for proxmox running on a node named ds2 on the URL https://proxmox.office.dsoderlund.consulting:8006/
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: proxmox-tls
namespace: office
spec:
secretName: proxmox-tls
dnsNames:
- "proxmox.office.dsoderlund.consulting"
duration: 720h0m0s # 30d
renewBefore: 240h0m0s # 10d
privateKey:
algorithm: RSA
encoding: PKCS1
size: 2048
usages:
- "digital signature"
- "key encipherment"
issuerRef:
name: letsencrypt-prod
kind: ClusterIssuer
---
apiVersion: batch/v1
kind: Job
metadata:
name: certupdater-proxmox
namespace: office
spec:
template:
metadata:
labels:
app: certupdater-proxmox
spec:
restartPolicy: Never
containers:
- name: certupdater-proxmox
image: docker.io/dsoderlund/proxmox_certupdater:latest
imagePullPolicy: Always
command:
- ./certupdater.py
args:
- --auth=/proxmox-creds/proxmox-certupdater-apitoken.txt
- --cert_dir=/certs
- --destination=proxmox.office.dsoderlund.consulting
- --node=ds2
volumeMounts:
- name: proxmox-creds
mountPath: "/proxmox-creds"
readOnly: true
- name: proxmox-certs
mountPath: "/certs"
readOnly: true
volumes:
- name: proxmox-creds
secret:
secretName: proxmox-certupdater-api-key
- name: proxmox-certs
secret:
secretName: proxmox-tls
Content type
Image
Digest
sha256:f04a8b5ff…
Size
21.5 MB
Last updated
about 1 month ago
docker pull dsoderlund/proxmox_certupdater