Sign inSign up

mecodia/cert-manager-webhook-hetzner

By mecodia

•Updated over 2 years ago

Image
0

50K+

mecodia/cert-manager-webhook-hetzner repository overview

ARCHIVED PROJECT

We recommend using https://github.com/vadimkim/cert-manager-webhook-hetzner⁠ instead.

⁠ACME Webhook for Hetzner DNS

This project provides a cert-manager⁠ ACME Webhook for Hetzner DNS⁠ and is based on the Example Webhook⁠

This README and the inspiration for this webhook was mostly taken from Stephan Müllers INWX Webhook⁠.

The Helm Chart is automatically published via github pages⁠.

⁠Requirements

⁠Last tested version combination
  • webhook image: v0.4.0
  • cert-manager: v1.12.5
  • kubernetes: v1.26.7

⁠Configuration

The following table lists the configurable parameters of the cert-manager chart and their default values.

ParameterDescriptionDefault
groupNameGroup name of the API service.dns.hetzner.cloud
certManager.namespaceNamespace where cert-manager is deployed to.kube-system
certManager.serviceAccountNameService account of cert-manager installation.cert-manager
image.repositoryImage repositorymecodia/cert-manager-webhook-hetzner
image.tagImage taglatest
image.pullPolicyImage pull policyAlways
service.typeAPI service typeClusterIP
service.portAPI service port443
resourcesCPU/memory resource requests/limits{}
nodeSelectorNode labels for pod assignment{}
affinityNode affinity for pod assignment{}
tolerationsNode tolerations for pod assignment[]

⁠Installation

⁠cert-manager

Follow the instructions⁠ using the cert-manager documentation to install it within your cluster.

⁠Webhook
git clone https://github.com/mecodia/cert-manager-webhook-hetzner.git
cd cert-manager-webhook-hetzner
helm install --namespace kube-system cert-manager-webhook-hetzner ./charts/cert-manager-webhook-hetzner

Note: The kubernetes resources used to install the Webhook should be deployed within the same namespace as the cert-manager.

To uninstall the webhook run

helm uninstall --namespace kube-system cert-manager-webhook-hetzner

⁠Issuer

Create a ClusterIssuer or Issuer resource as following:

apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
  name: letsencrypt-staging
spec:
  acme:
    # The ACME server URL (attention, this is the staging one!)
    server: https://acme-staging-v02.api.letsencrypt.org/directory

    # Email address used for ACME registration
    email: [email protected] # REPLACE THIS WITH YOUR EMAIL!!!

    # Name of a secret used to store the ACME account private key
    privateKeySecretRef:
      name: letsencrypt-staging-account-key

    solvers:
      - dns01:
          webhook:
            groupName: dns.hetzner.cloud
            solverName: hetzner
            config:
              APIKey: <YOUR-DNS-API-KEY-HERE>
⁠Credentials

For accessing the Hetzner DNS API, you need an API Token which you can create in the DNS Console⁠.

Currently, we don't provide a way to use secrets for you API KEY.

⁠Create a certificate

Finally, you can create certificates, for example:

apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
  name: example-wildcard-cert
  namespace: cert-manager
spec:
  commonName: "*.example.com"
  dnsNames:
    - "*.example.com"
  issuerRef:
    kind: ClusterIssuer
    name: letsencrypt-staging
  secretName: example-cert

⁠Development

⁠Requirements
⁠Running the test suite
  1. Create a new test account at Hetzner DNS Console⁠ or use an existing account

  2. Go to testdata/hcloud-dns/config.json and replace your api key.

  3. Download dependencies

    go mod download
    
  4. Run tests (replace zone name with one of your zones)

    env TEST_ZONE_NAME='warbl.net.' make test
    

⁠Releases

Dockerhub is set up to automatically build images from tagged commits.

Example tags are:

cert-manager-webhook-hetzner-0.3.0-rc4
cert-manager-webhook-hetzner-0.3.0
cert-manager-webhook-hetzner-0.1
cert-manager-webhook-hetzner-1.1

Github should take care of the helm chart updates.

Tag summary

Content type

Image

Digest

sha256:c88657cd9…

Size

21.2 MB

Last updated

over 2 years ago

docker pull mecodia/cert-manager-webhook-hetzner