{"body":"15:07:35 <portdirect> so - it think the planets are alining for internal tls\n15:07:43 <portdirect> we have had a few rough starts on this before\n15:08:10 <portdirect> but evaluating jetstacks cert manager, it looks to be the missing link in what was attempted before\n15:08:30 <portdirect> id therefore like to propose that we use that to get this effort moving again\n15:08:49 <portdirect> which we could break down into a couple of steps:\n15:09:18 <portdirect> 1) Jetstack Cert Manager\n15:09:18 <portdirect> a) Chart\n15:09:18 <portdirect> b) Deploy in gate with snakeoil ca\n15:09:18 <portdirect> 2) Chart updates\n15:09:18 <portdirect> a) Add in option to create TLS cr, with required hostnames - ideally via htk macro similar to the ingress rule generator\n15:09:19 <portdirect> b) Get tls certs generated for all internal services\n15:09:19 <portdirect> c) Mount secrets into api pods\n15:09:20 <portdirect> d) Enable tls and also set the ingress rule to support secure backends","name":"","extension":"txt","url":"https://www.irccloud.com/pastebin/md3BsAIa","modified":1590505895,"id":"md3BsAIa","size":976,"lines":13,"own_paste":false,"theme":"","date":1590505895}