kubetrust image injects custom/private CAs to Kubernetes pods github.com/kubetrust/kubetrust
190
kubetrust is a Kubernetes mutating admission webhook that automatically injects CA certificates into pods running in labeled namespaces. It integrates with cert-manager's trust-manager to consolidate system CAs and custom CA certificates into a single trust bundle, then mounts that bundle into application pods at runtime. Key Features
✅ Runtime Configuration - No hardcoded certificates, fully configurable via Helm
✅ Zero-Downtime CA Updates - Update CA certificates without rebuilding images or application downtime
✅ Automatic Certificate Generation - Helm hooks generate webhook TLS certificates automatically
✅ Custom CA Support - Easily inject your organization's CA certificates
✅ trust-manager Integration - Automatically installed as a subchart for CA bundle management
✅ Namespace-Based Injection - Control which namespaces receive CA certificates via labels
✅ Single Image - One container image works across all deployments
✅ Production Ready - High availability support, documented best practices
Project Homepage: https://github.com/kubetrust/kubetrust
Content type
Image
Digest
sha256:def38b587…
Size
7 MB
Last updated
10 months ago
docker pull karthickk/kubetrust:v1.1