Terminate TLS on OpenBao with a cert-manager self-signed certificate

Adds a ClusterIssuer (selfSigned) + Certificate, mounts the resulting
secret into the OpenBao pod, and switches the listener config from
tls_disable=1 to a TLS-enabled listener. UI/API is now served over
https://<node-ip>:30200 instead of plain HTTP.

Also updates ClusterSecretStore/bootstrap Job to use https + trust the
self-signed cert via caProvider/BAO_SKIP_VERIFY.

Co-authored-by: Copilot <[email protected]>
This commit is contained in:
2026-09-18 20:20:20 +02:00
co-authored by Copilot
parent ffaf7247fe
commit 5ef5aaa0d8
5 changed files with 109 additions and 3 deletions
+35
View File
@@ -0,0 +1,35 @@
{{- if .Values.tls.enabled }}
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: openbao-selfsigned
spec:
selfSigned: {}
---
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: {{ .Values.tls.secretName }}
namespace: {{ .Release.Namespace }}
spec:
secretName: {{ .Values.tls.secretName }}
duration: {{ .Values.tls.duration }}
renewBefore: {{ .Values.tls.renewBefore }}
issuerRef:
name: openbao-selfsigned
kind: ClusterIssuer
dnsNames:
- {{ include "openbao-gitops.openbaoFullname" . }}
- {{ include "openbao-gitops.openbaoFullname" . }}.{{ .Release.Namespace }}
- {{ include "openbao-gitops.openbaoFullname" . }}.{{ .Release.Namespace }}.svc
- {{ include "openbao-gitops.openbaoFullname" . }}.{{ .Release.Namespace }}.svc.cluster.local
- localhost
{{- range .Values.tls.dnsNames }}
- {{ . }}
{{- end }}
ipAddresses:
- "127.0.0.1"
{{- range .Values.tls.ipAddresses }}
- {{ . | quote }}
{{- end }}
{{- end }}