Configuring an ACME issuer by using explicit credentials for AWS Route53
You can use cert-manager Operator for Red Hat OpenShift to set up an Automated Certificate Management Environment (ACME) issuer to solve DNS-01 challenges by using explicit credentials on AWS. This procedure uses Let’s Encrypt as the ACME certificate authority (CA) server and shows how to solve DNS-01 challenges with Amazon Route 53.
-
You must provide the explicit
accessKeyIDandsecretAccessKeycredentials. For more information, see Route53 in the upstream cert-manager documentation.You can use Amazon Route 53 with explicit credentials in an Red Hat OpenShift Container Platform cluster that is not running on AWS.
-
Optional: Override the name server settings for the DNS-01 self check.
This step is required only when the target public-hosted zone overlaps with the cluster’s default private-hosted zone.
-
Edit the
CertManagerresource by running the following command:$ oc edit certmanager cluster -
Add a
spec.controllerConfigsection with the following override arguments:apiVersion: operator.openshift.io/v1alpha1 kind: CertManager metadata: name: cluster ... spec: ... controllerConfig: overrideArgs: - '--dns01-recursive-nameservers-only' - '--dns01-recursive-nameservers=1.1.1.1:53'where:
--dns01-recursive-nameservers-only-
Specifies recursive name servers instead of checking the authoritative name servers associated with that domain.
--dns01-recursive-nameservers=1.1.1.1:53-
Specifies a comma-separated list of
<host>:<port>names servers to query for the DNS-01 self check. You must use a1.1.1.1:53value to avoid the public and private zones overlapping.
-
Save the file to apply the changes.
-
-
Optional: Create a namespace for the issuer:
$ oc new-project <issuer_namespace> -
Create a secret to store your AWS credentials in by running the following command:
$ oc create secret -n my-issuer-namespace generic aws-secret \ --from-literal=awsSecretAccessKey=<aws_secret_access_key>Replace
<aws_secret_access_key>with your AWS secret access key. -
Create an issuer:
-
Create a YAML file that defines the
Issuerobject:Exampleissuer.yamlfileapiVersion: cert-manager.io/v1 kind: Issuer metadata: name: <issuer_name> namespace: <issuer_namespace> spec: acme: server: <server> email: "<email_address>" privateKeySecretRef: name: <secret_private_key> solvers: - dns01: route53: accessKeyID: <aws_key_id> hostedZoneID: <hosted_zone_id> region: <region_name> secretAccessKeySecretRef: name: "<aws_secret>" key: "<aws_secret_access_key>"where:
<issuer_name>-
Specifies a name for the issuer.
<issuer_namespace>-
Specifies the namespace that you created for the issuer.
server-
Specifies the URL to access the ACME server’s
directoryendpoint. This example uses the Let’s Encrypt staging environment. <email_address>-
Specifies your email address.
<secret_private_key>-
Specifies the name of the secret to store the ACME account private key in.
<aws_key_id>-
Specifies your AWS key ID.
<hosted_zone_id>-
Specifies your hosted zone ID.
<region_name>-
Specifies the AWS region name. For example,
us-east-1. <aws_secret>-
Specifies the name of the secret you created.
<aws_secret_access_key>-
Specifies the key in the secret you created that stores your AWS secret access key.
-
Create the
Issuerobject by running the following command:$ oc create -f issuer.yaml
-