tls-secrets.yaml 1.9 KB

123456789101112131415161718192021222324252627282930
  1. {{- /*
  2. Copyright VMware, Inc.
  3. SPDX-License-Identifier: APACHE-2.0
  4. */}}
  5. {{- if (include "postgresql.v1.createTlsSecret" . ) }}
  6. {{- $secretName := printf "%s-crt" (include "common.names.fullname" .) }}
  7. {{- $ca := genCA "postgresql-ca" 365 }}
  8. {{- $fullname := include "common.names.fullname" . }}
  9. {{- $releaseNamespace := .Release.Namespace }}
  10. {{- $clusterDomain := .Values.clusterDomain }}
  11. {{- $primaryHeadlessServiceName := include "postgresql.v1.primary.svc.headless" . }}
  12. {{- $readHeadlessServiceName := include "postgresql.v1.readReplica.svc.headless" . }}
  13. {{- $altNames := list (printf "*.%s.%s.svc.%s" $fullname $releaseNamespace $clusterDomain) (printf "%s.%s.svc.%s" $fullname $releaseNamespace $clusterDomain) (printf "*.%s.%s.svc.%s" $primaryHeadlessServiceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc.%s" $primaryHeadlessServiceName $releaseNamespace $clusterDomain) (printf "*.%s.%s.svc.%s" $readHeadlessServiceName $releaseNamespace $clusterDomain) (printf "%s.%s.svc.%s" $readHeadlessServiceName $releaseNamespace $clusterDomain) $fullname }}
  14. {{- $cert := genSignedCert $fullname nil $altNames 365 $ca }}
  15. apiVersion: v1
  16. kind: Secret
  17. metadata:
  18. name: {{ $secretName }}
  19. namespace: {{ .Release.Namespace | quote }}
  20. labels: {{- include "common.labels.standard" ( dict "customLabels" .Values.commonLabels "context" $ ) | nindent 4 }}
  21. {{- if .Values.commonAnnotations }}
  22. annotations: {{- include "common.tplvalues.render" ( dict "value" .Values.commonAnnotations "context" $ ) | nindent 4 }}
  23. {{- end }}
  24. type: kubernetes.io/tls
  25. data:
  26. tls.crt: {{ include "common.secrets.lookup" (dict "secret" $secretName "key" "tls.crt" "defaultValue" $cert.Cert "context" $) }}
  27. tls.key: {{ include "common.secrets.lookup" (dict "secret" $secretName "key" "tls.key" "defaultValue" $cert.Key "context" $) }}
  28. ca.crt: {{ include "common.secrets.lookup" (dict "secret" $secretName "key" "ca.crt" "defaultValue" $ca.Cert "context" $) }}
  29. {{- end }}