Skip to content

TLS certificates with cert-manager

The enum webhook for cert-manager solves ACME DNS-01 challenges for zones hosted on enum DNS. Use it to issue certificates from Let’s Encrypt or any other ACME CA, including wildcard certificates, which HTTP-01 validation cannot issue.

For each challenge, the webhook creates the _acme-challenge TXT record through the enum API and removes it once validation completes. The record shows up in your zone like any other record while it exists.

  • A Kubernetes cluster with cert-manager installed
  • An active enum DNS zone for the domain (its registrar nameservers point at enum). See How it works
  • enumctl set up with the project that owns the zone. See the Quickstart
  1. Install the webhook into the cert-manager namespace:

    Terminal window
    helm install cert-manager-webhook-enum \
    oci://registry.enum.cloud/enum/charts/cert-manager-webhook-enum \
    --namespace cert-manager
  2. Store an API token for the project in a Secret. A service account with a key keeps the token independent of your own login:

    Terminal window
    kubectl -n cert-manager create secret generic enum-api-token \
    --from-literal=token="$(enumctl sa create cert-manager --key cert-manager --print-token-only)"

    Keys expire after 90 days by default. Pass --expires-in, --expires-at, or --no-expiry to enumctl sa create to change that. Rotate a key with enumctl sa keys create and update the Secret before the old one expires.

  3. Create an issuer that uses the webhook. Look up your project ID with enumctl projects list:

    apiVersion: cert-manager.io/v1
    kind: ClusterIssuer
    metadata:
    name: enum-letsencrypt
    spec:
    acme:
    server: https://acme-v02.api.letsencrypt.org/directory
    email: you@example.com
    privateKeySecretRef:
    name: enum-letsencrypt-account-key
    solvers:
    - dns01:
    webhook:
    groupName: acme.enum.co
    solverName: enum
    config:
    projectId: <your-project-id>
    apiTokenSecretRef:
    name: enum-api-token
    key: token
  4. Request a certificate:

    apiVersion: cert-manager.io/v1
    kind: Certificate
    metadata:
    name: example-com
    spec:
    secretName: example-com-tls
    issuerRef:
    name: enum-letsencrypt
    kind: ClusterIssuer
    dnsNames:
    - example.com
    - "*.example.com"

    Check progress with kubectl describe certificate example-com. Once it is ready, the certificate and key are in the example-com-tls Secret.

FieldRequiredDescription
projectIdyesThe enum project that owns the zone
apiTokenSecretRefyesname and key of the Secret holding the API token
apiUrlnoenum API endpoint. Defaults to api.enum.co:443

groupName must be acme.enum.co and solverName must be enum.

ValueDefaultDescription
secretNames[enum-api-token]Secrets the webhook may read. Add your Secret’s name here if you use a different one
certManager.namespacecert-managerNamespace of your cert-manager installation
certManager.serviceAccountNamecert-managercert-manager’s ServiceAccount, allowed to call the webhook

The source is on GitHub.