cert-manager
cert-manager issues and renews TLS certificates inside Kubernetes from the issuers it is given. The GCP Web App Blueprint uses it for one job only: an internal certificate authority (CA) for the cluster's internal hostnames, such as the ArgoCD UI.
What it does
A ClusterIssuer is a cluster-wide source of certificates: a self-signed issuer, a CA whose key sits in a Kubernetes Secret, or an ACME service. A Certificate object asks an issuer for a certificate for some DNS names and keeps it in a Secret, renewing it before expiry. A CA ClusterIssuer reads its key from cert-manager's own namespace.
How BuiltForProd uses it
The cert-manager unit installs the cert-manager chart v1.21.2 with its CRDs into the cert-manager namespace, on the tainted system pool, and builds a three-step chain:
| Object | Kind | What it is |
|---|---|---|
selfsigned-bootstrap | ClusterIssuer | A self-signed issuer used only to sign the root |
internal-root-ca | Certificate | The root CA of the stage: ECDSA P-384, ten years, renewed a year ahead |
internal-ca | ClusterIssuer | The CA issuer every internal certificate comes from |
What it issues. The argocd unit requests argocd-tls for argocd.<stage>.internal.company.com from internal-ca: ECDSA P-256, valid 90 days, renewed 30 days ahead with a new key each time. The internal GKE Gateway of ArgoCD terminates TLS with it. Workstations and runners trust these certificates by importing ca.crt from the Secret cert-manager/internal-root-ca.
What it does not issue. The public hostnames blueprint-api and blueprint-app use Google-managed certificates from Certificate Manager, validated through DNS. cert-manager therefore has no ACME issuer and no Cloud DNS access.
Terms you will see
| Term | Meaning |
|---|---|
| ClusterIssuer | A cluster-wide certificate source. |
| Certificate | A request for a certificate, kept and renewed in a Secret. |
internal-ca | The stage's internal CA issuer. |
| Root CA | internal-root-ca, the certificate clients import to trust the chain. |
Where to read more
- GCP Web App Blueprint overview for the internal hostnames.
- Certificate Manager for the public certificates.
- ArgoCD for the internal UI that uses the CA.