Hacker News new | past | comments | ask | show | jobs | submit | harrisonpowers's favorites login


I use https://github.com/jetstack/kube-lego and so far it works . I didn't get the to 90 day expiry yet, but it successfully automatically acquired the first certificate. I heard good things from people who have been using it for a while.

I recommend the nginx as ingress backend ( https://github.com/jetstack/kube-lego/tree/master/examples/n... ), as GCE had problems talking over https. Also wait for a bit (e.g. 30 minutes) after updating your domain records and enabling kube-lego (i.e. just before this section: https://github.com/jetstack/kube-lego/tree/master/examples/n... ).


I'm using this for rolling out test environments and so far it works amazingly well. Wildcard DNS record to an ELB, and with just the one kube-lego pod + the one single ingress annotation i automatically get new environments provisioned in under 10 minutes including app bootstrap. As a recovering sysadmin (some fools now call me devops;) this is stuff i thought of being the holy grail 5 years ago.

Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: