wip: Use cert-manager for cnpg's auth

This commit is contained in:
2025-07-16 09:22:15 +02:00
parent 2387f2dab7
commit 4f19e13f3e
6 changed files with 78 additions and 40 deletions
+16
View File
@@ -0,0 +1,16 @@
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: postgres-cluster-ca
spec:
secretName: postgres-cluster-ca
secretTemplate:
labels:
cnpg.io/reload: ""
usages:
- client auth
commonName: streaming_replica
issuerRef:
name: selfsigned
kind: ClusterIssuer
group: cert-manager.io
+22
View File
@@ -0,0 +1,22 @@
apiVersion: postgresql.cnpg.io/v1
kind: Cluster
metadata:
name: postgres-cluster
namespace: postgres
spec:
instances: 3
storage:
size: 10Gi
certificates:
clientCASecret: postgres-cert-ca
replicationTLSSecret: postgres-cert-ca
# this is here because no `Role` crd exsists yet.
# see https://github.com/cloudnative-pg/cloudnative-pg/issues/5341
managed:
roles:
- name: authentik
login: true
disablePassword: true