Improve mentions of CS CA in managing-tls-in-a-cluster (#30347)
* Improve mentions of CS CA in managing-tls-in-a-cluster * Update content/en/docs/tasks/tls/managing-tls-in-a-cluster.md Co-authored-by: Tim Bannister <tim@scalefactory.com> * Update managing-tls-in-a-cluster.md * Update managing-tls-in-a-cluster.md Co-authored-by: Tim Bannister <tim@scalefactory.com>
This commit is contained in:
@@ -18,7 +18,7 @@ draft](https://github.com/ietf-wg-acme/acme/).
|
|||||||
|
|
||||||
{{< note >}}
|
{{< note >}}
|
||||||
Certificates created using the `certificates.k8s.io` API are signed by a
|
Certificates created using the `certificates.k8s.io` API are signed by a
|
||||||
dedicated CA. It is possible to configure your cluster to use the cluster root
|
[dedicated CA](#a-note-to-cluster-administrators). It is possible to configure your cluster to use the cluster root
|
||||||
CA for this purpose, but you should never rely on this. Do not assume that
|
CA for this purpose, but you should never rely on this. Do not assume that
|
||||||
these certificates will validate against the cluster root CA.
|
these certificates will validate against the cluster root CA.
|
||||||
{{< /note >}}
|
{{< /note >}}
|
||||||
@@ -42,16 +42,25 @@ install it via your operating system's software sources, or fetch it from
|
|||||||
|
|
||||||
## Trusting TLS in a cluster
|
## Trusting TLS in a cluster
|
||||||
|
|
||||||
Trusting the custom CA from an application running as a pod usually requires
|
Trusting the [custom CA](#a-note-to-cluster-administrators) from an application running as a pod usually requires
|
||||||
some extra application configuration. You will need to add the CA certificate
|
some extra application configuration. You will need to add the CA certificate
|
||||||
bundle to the list of CA certificates that the TLS client or server trusts. For
|
bundle to the list of CA certificates that the TLS client or server trusts. For
|
||||||
example, you would do this with a golang TLS config by parsing the certificate
|
example, you would do this with a golang TLS config by parsing the certificate
|
||||||
chain and adding the parsed certificates to the `RootCAs` field in the
|
chain and adding the parsed certificates to the `RootCAs` field in the
|
||||||
[`tls.Config`](https://godoc.org/crypto/tls#Config) struct.
|
[`tls.Config`](https://godoc.org/crypto/tls#Config) struct.
|
||||||
|
|
||||||
You can distribute the CA certificate as a
|
{{< note >}}
|
||||||
[ConfigMap](/docs/tasks/configure-pod-container/configure-pod-configmap) that your
|
Even though the custom CA certificate may be included in the filesystem (in the
|
||||||
pods have access to use.
|
ConfigMap `kube-root-ca.crt`),
|
||||||
|
you should not use that certificate authority for any purpose other than to verify internal
|
||||||
|
Kubernetes endpoints. An example of an internal Kubernetes endpoint is the
|
||||||
|
Service named `kubernetes` in the default namespace.
|
||||||
|
|
||||||
|
If you want to use a custom certificate authority for your workloads, you should generate
|
||||||
|
that CA separately, and distribute its CA certificate using a
|
||||||
|
[ConfigMap](/docs/tasks/configure-pod-container/configure-pod-configmap) that your pods
|
||||||
|
have access to read.
|
||||||
|
{{< /note >}}
|
||||||
|
|
||||||
## Requesting a certificate
|
## Requesting a certificate
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user