{"id":13646600,"url":"https://github.com/kelseyhightower/certificate-init-container","last_synced_at":"2025-04-30T01:33:15.876Z","repository":{"id":39618236,"uuid":"87385240","full_name":"kelseyhightower/certificate-init-container","owner":"kelseyhightower","description":"Bootstrap TLS certificates for Pods using the Kubernetes certificates API.","archived":false,"fork":false,"pushed_at":"2020-02-17T15:23:33.000Z","size":8073,"stargazers_count":146,"open_issues_count":11,"forks_count":52,"subscribers_count":10,"default_branch":"master","last_synced_at":"2024-08-02T01:26:17.737Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/kelseyhightower.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2017-04-06T04:10:10.000Z","updated_at":"2024-03-10T15:36:50.000Z","dependencies_parsed_at":"2022-09-16T14:20:31.592Z","dependency_job_id":null,"html_url":"https://github.com/kelseyhightower/certificate-init-container","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kelseyhightower%2Fcertificate-init-container","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kelseyhightower%2Fcertificate-init-container/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kelseyhightower%2Fcertificate-init-container/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kelseyhightower%2Fcertificate-init-container/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/kelseyhightower","download_url":"https://codeload.github.com/kelseyhightower/certificate-init-container/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":223880244,"owners_count":17219086,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-02T01:03:00.503Z","updated_at":"2024-11-09T20:30:23.783Z","avatar_url":"https://github.com/kelseyhightower.png","language":"Go","funding_links":[],"categories":["Go"],"sub_categories":[],"readme":"# Certificate Init Container\n\nThe `certificate-init-container` generates TLS certificates for pods using the [Kubernetes certificate API](https://kubernetes.io/docs/tasks/tls/managing-tls-in-a-cluster).\n\nSee the [current release](#current-release) for usage details.\n\n## Prerequisites\n\n* Kubernetes 1.6.0+\n\n## Usage\n\nCreate a deployment that uses the `certificate-init-container`:\n\n```\nkubectl create -f deployments/tls-app.yaml\n```\n\nThe `certificate-init-container` will generate a private key, certificate signing request (csr), and submit a certificate signing request to the Kubernetes certificate API, then wait for the [certificate to be approved](https://kubernetes.io/docs/tasks/tls/managing-tls-in-a-cluster/#approving-certificate-signing-requests).\n\n```\nkubectl get pods\n```\n```\nNAME                       READY     STATUS     RESTARTS   AGE\ntls-app-2342064067-c9xwf   0/1       Init:0/1   0          5s\n```\n\nView the `certificate-init-container` logs for more details:\n\n```\nkubectl logs tls-app-2342064067-c9xwf -c certificate-init-container\n```\n```\n2017/04/06 06:58:02 wrote /etc/tls/tls.key\n2017/04/06 06:58:02 wrote /etc/tls/tls.csr\n2017/04/06 06:58:02 waiting for certificate...\n2017/04/06 06:58:02 certificate signing request (tls-app-2342064067-c9xwf-default) not approved; trying again in 5 seconds\n2017/04/06 06:58:27 certificate signing request (tls-app-2342064067-c9xwf-default) not approved; trying again in 5 seconds\n```\n\nList the certificate signing requests and locate the csr pending for the `tls-app` pod:\n\n```\nkubectl get csr\n```\n```\nNAME                               AGE       REQUESTOR                               CONDITION\ntls-app-2342064067-c9xwf-default   1m        system:serviceaccount:default:default   Pending\n```\n\nReview the csr details:\n\n```\nkubectl describe csr tls-app-2342064067-c9xwf-default\n```\n\n```\nName:                   tls-app-2342064067-c9xwf-default\nLabels:                 \u003cnone\u003e\nAnnotations:            \u003cnone\u003e\nCreationTimestamp:      Thu, 06 Apr 2017 06:17:16 -0700\nRequesting User:        system:serviceaccount:default:default\nStatus:                 Pending\nSubject:\n        Common Name:    10-228-0-10.default.pod.cluster.local\n        Serial Number:\nSubject Alternative Names:\n        DNS Names:      10-228-0-10.default.pod.cluster.local\n                        example.com\n                        tls-app.default.svc.cluster.local\n        IP Addresses:   10.228.0.10\n                        127.0.0.1\nEvents:\t\u003cnone\u003e\n```\n\nApprove the pending certificate signing request:\n\n```\nkubectl certificate approve tls-app-2342064067-c9xwf-default\n```\n```\ncertificatesigningrequest \"tls-app-2342064067-c9xwf-default\" approved\n```\n\nOnce the certificate signing request has been approved the `certificate-init-container` will fetch the signed certificate and write it to a shared filesystem.\n\n```\nkubectl logs tls-app-2342064067-c9xwf -c certificate-init-container\n```\n```\n2017/04/06 06:58:02 wrote /etc/tls/tls.key\n2017/04/06 06:58:02 wrote /etc/tls/tls.csr\n2017/04/06 06:58:02 waiting for certificate...\n2017/04/06 06:58:02 certificate signing request (tls-app-2342064067-c9xwf-default) not approved; trying again in 5 seconds\n2017/04/06 06:58:27 certificate signing request (tls-app-2342064067-c9xwf-default) not approved; trying again in 5 seconds\n...\n2017/04/06 07:00:28 wrote /etc/tls/tls.crt\n```\n\nNext the `certificate-init-container` will exit and the pod will start the remaining containers which will have access to the certificate and private key.\n\n```\nkubectl get pods\n```\n```\nNAME                       READY     STATUS    RESTARTS   AGE\ntls-app-2342064067-c9xwf   1/1       Running   0          2m\n```\n\nCreate a service for the `tls-app` deployment to view the certificate details.\n\n```\nkubectl expose deployment tls-app --type=LoadBalancer\n```\n\n## Current Release\n\nContainer Image:\n\n```\ngcr.io/hightowerlabs/certificate-init-container:0.0.1\n```\n\nSee the [example deployment](deployments/tls-app.yaml) for more details.\n\nUsage:\n\n```\ncertificate-init-container -h\n```\n```\nUsage of certificate-init-container:\n  -additional-dnsnames string\n    \tadditional dns names; comma separated\n  -cert-dir string\n    \tThe directory where the TLS certs should be written (default \"/etc/tls\")\n  -cluster-domain string\n    \tKubernetes cluster domain (default \"cluster.local\")\n  -hostname string\n    \thostname as defined by pod.spec.hostname\n  -namespace string\n    \tnamespace as defined by pod.metadata.namespace (default \"default\")\n  -pod-ip string\n    \tIP address as defined by pod.status.podIP\n  -pod-name string\n    \tname as defined by pod.metadata.name\n  -service-ips string\n    \tservice IP addresses that resolve to this Pod; comma separated\n  -service-names string\n    \tservice names that resolve to this Pod; comma separated\n  -subdomain string\n    \tsubdomain as defined by pod.spec.subdomain\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkelseyhightower%2Fcertificate-init-container","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fkelseyhightower%2Fcertificate-init-container","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkelseyhightower%2Fcertificate-init-container/lists"}