-
Notifications
You must be signed in to change notification settings - Fork 196
gcp managed cert config
- Use Google-managed SSL certificates
You can use Google-managed SSL certificates to secure your custom domain with HTTPS. Google-managed SSL certificates are provisioned, renewed, and managed for your domain by Google. You can use Google-managed SSL certificates with Google Kubernetes Engine (GKE) and Google Cloud Load Balancing.
Comprehensive documentation is available at Google-managed SSL certificates.
- Don't support wildcard domains.
- The domain name must be no longer than 63 characters.
- Your ingressClassName must be "gce".
- You must apply Ingress and ManagedCertificate resources in the same project and namespace.
- Install the Google Cloud CLI.
- Install kubectl.
- Set up default gcloud settings.
- Set up Environment Variables.
- Get cluster credentials for kubectl
To add a Google-managed SSL certificate to your ReportPortal deployment, you need to set the following parameters:
helm install \
...
--set ingress.tls.certificate.gcpManaged=true
--set ingress.hosts[0]="example.com"
...
Helm creates a ManagedCertificate resource and an Ingress resource that references the ManagedCertificate resource.
GKE automatically provisions the certificate and configures the load balancer to use it.
Create a ManagedCertificate resource in gcp-managed-cert.yaml to request a Google-managed SSL certificate for your domain.
# gcp-managed-cert.yaml
apiVersion: networking.gke.io/v1
kind: ManagedCertificate
metadata:
name: gcp-managed-certificate
spec:
domains:
- FQDN_1
- FQDN_2FQDN_1, FQDN_2: Fully-qualified domain names that you own. For example, example.com.
Apply the configuration:
kubectl apply -f gcp-managed-cert.yamlNote: Replace
{APP_NAME}with your application name.
If you have tls section in your Ingress resource, remove it.
kubectl edit ingress ${APP_NAME}-gateway-ingressUpdate the Ingress resource to reference the ManagedCertificate resource:
kubectl annotate ingress ${APP_NAME}-gateway-ingress networking.gke.io/managed-certificates=gcp-managed-certificateTo check the status of the certificate, run the following command:
kubectl describe managedcertificateIn the output, look for the Status. The status contains Certificate Status.
Certificate Name is the GCP managed certificate name.
To check all GCP managed certificates, run the following command:
gcloud compute ssl-certificates list --globalYou need to find the certificate by the Google generated name and check the MANAGED_STATUS column.
You can get Google generated name from the Certificate Name using kubectl.
If you want to disable HTTP Load Balancing, you can do it after the certificate is attached to the Ingress resource:
kubectl annotate ingress ${APP_NAME}-gateway-ingress kubernetes.io/ingress.allow-http=falseTo delete the ManagedCertificate resource:
kubectl delete managedcertificate gcp-managed-certificateRemove the ManagedCertificate reference from the Ingress resource:
kubectl annotate ingress managed-cert-ingress networking.gke.io/gcp-managed-certificate-Also, check that the certificate is removed from the Google Cloud Console
gcloud compute ssl-certificates list --globalIf the certificate is still present, delete it:
gcloud compute ssl-certificates delete ${CERTIFICATE_NAME} --global