TLS certificates with cert-manager
The enum webhook for cert-manager solves ACME DNS-01 challenges for zones hosted on enum DNS. Use it to issue certificates from Let’s Encrypt or any other ACME CA, including wildcard certificates, which HTTP-01 validation cannot issue.
For each challenge, the webhook creates the _acme-challenge TXT record through the enum API and removes it once validation completes. The record shows up in your zone like any other record while it exists.
Prerequisites
Section titled “Prerequisites”- A Kubernetes cluster with cert-manager installed
- An active enum DNS zone for the domain (its registrar nameservers point at enum). See How it works
enumctlset up with the project that owns the zone. See the Quickstart
Set up
Section titled “Set up”-
Install the webhook into the cert-manager namespace:
Terminal window helm install cert-manager-webhook-enum \oci://registry.enum.cloud/enum/charts/cert-manager-webhook-enum \--namespace cert-manager -
Store an API token for the project in a Secret. A service account with a key keeps the token independent of your own login:
Terminal window kubectl -n cert-manager create secret generic enum-api-token \--from-literal=token="$(enumctl sa create cert-manager --key cert-manager --print-token-only)"Keys expire after 90 days by default. Pass
--expires-in,--expires-at, or--no-expirytoenumctl sa createto change that. Rotate a key withenumctl sa keys createand update the Secret before the old one expires. -
Create an issuer that uses the webhook. Look up your project ID with
enumctl projects list:apiVersion: cert-manager.io/v1kind: ClusterIssuermetadata:name: enum-letsencryptspec:acme:server: https://acme-v02.api.letsencrypt.org/directoryemail: you@example.comprivateKeySecretRef:name: enum-letsencrypt-account-keysolvers:- dns01:webhook:groupName: acme.enum.cosolverName: enumconfig:projectId: <your-project-id>apiTokenSecretRef:name: enum-api-tokenkey: token -
Request a certificate:
apiVersion: cert-manager.io/v1kind: Certificatemetadata:name: example-comspec:secretName: example-com-tlsissuerRef:name: enum-letsencryptkind: ClusterIssuerdnsNames:- example.com- "*.example.com"Check progress with
kubectl describe certificate example-com. Once it is ready, the certificate and key are in theexample-com-tlsSecret.
Solver config
Section titled “Solver config”| Field | Required | Description |
|---|---|---|
projectId | yes | The enum project that owns the zone |
apiTokenSecretRef | yes | name and key of the Secret holding the API token |
apiUrl | no | enum API endpoint. Defaults to api.enum.co:443 |
groupName must be acme.enum.co and solverName must be enum.
Chart values
Section titled “Chart values”| Value | Default | Description |
|---|---|---|
secretNames | [enum-api-token] | Secrets the webhook may read. Add your Secret’s name here if you use a different one |
certManager.namespace | cert-manager | Namespace of your cert-manager installation |
certManager.serviceAccountName | cert-manager | cert-manager’s ServiceAccount, allowed to call the webhook |
The source is on GitHub.