Skip to content
Snippets Groups Projects
Unverified Commit 61e8b353 authored by Varac's avatar Varac
Browse files

Try to reuse ACME account key

parent a285398c
No related branches found
No related tags found
No related merge requests found
......@@ -10,6 +10,7 @@ set -euo pipefail
# Create secret with HMAC key
b64secret=$(echo -n "${ZEROSSL_EAB_HMAC_KEY}" | base64 -w0)
b64tlskey=$(echo -n "${ZEROSSL_TLS_KEY}" | base64 -w0)
# Wait until cert-manager is ready
"$(dirname "$0")/retry_cmd_until_success.sh" 30 10 "flux get kustomization --status-selector ready=true --no-header | grep '^core'"
......@@ -19,6 +20,14 @@ kubectl apply -n cert-manager -f - <<EOF
---
apiVersion: v1
kind: Secret
metadata:
namespace: cert-manager
name: zerossl-prod
data:
tls.key: ${b64tlskey}
---
apiVersion: v1
kind: Secret
metadata:
namespace: cert-manager
name: zerossl-eabsecret
......@@ -38,7 +47,8 @@ spec:
keySecretRef:
name: zerossl-eabsecret
key: secret
# Name of a secret used to store the ACME account private key
# Name of the secret used to get the ACME account private key
disableAccountKeyGeneration: true
privateKeySecretRef:
name: zerossl-prod
solvers:
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment