- 先创建ca: o `bash create-ca.sh` - 后创建cert&key `bash create-certificate.sh domain.com` - 最后导入到k8s `bash import_to_k8s.sh`