# Values for the cert-manager Google CAS issuer chart.## Only the ServiceAccount ANNOTATION is set, not its name: the chart derives the# KSA name from the release name and its schema rejects serviceAccount.name.# That annotation is what binds the pod to the Google service account through# Workload Identity - the matching binding is in ../../cas.tf.serviceAccount:annotations:iam.gke.io/gcp-service-account:sa-google-cas-issuer@saudi-dev-gke-0.iam.gserviceaccount.comimage:repository:asia-south1-docker.pkg.dev/saudi-prod-artifacts-0/shared-docker/cert-manager-google-cas-issuer
# Values for the cert-manager chart. Each of these is load-bearing for a reason# recorded in FAST-DEPLOYMENT-LOG.md - none is cosmetic.# The CAS issuer's custom resources need cert-manager's CRDs, so they ship with# the chart rather than out of band.crds:enabled:true# REQUIRED ON AUTOPILOT. cert-manager puts its leader-election lease in# kube-system by default and Autopilot refuses writes there:# leases.coordination.k8s.io is forbidden ... namespace "kube-system"# GKE Warden authz [denied by managed-namespaces-limitation]# Without this the controller and cainjector run but never win leadership, so# cainjector never injects the CA bundle into the webhook configuration and every# Certificate fails with "x509: certificate signed by unknown authority".# The pods still report Running, so no health check catches it.global:leaderElection:namespace:cert-manager# Image repositories. The chart defaults EVERY component to quay.io, so each one# is redirected individually - overriding the chart source alone would leave the# pods still pulling externally while appearing migrated.image:repository:asia-south1-docker.pkg.dev/saudi-prod-artifacts-0/shared-docker/cert-manager-controllerwebhook:image:repository:asia-south1-docker.pkg.dev/saudi-prod-artifacts-0/shared-docker/cert-manager-webhookcainjector:image:repository:asia-south1-docker.pkg.dev/saudi-prod-artifacts-0/shared-docker/cert-manager-cainjectoracmesolver:image:repository:asia-south1-docker.pkg.dev/saudi-prod-artifacts-0/shared-docker/cert-manager-acmesolverstartupapicheck:# startupapicheck is a post-install Helm HOOK JOB that calls the cert-manager# API to prove it answers. On Autopilot it reliably fails with# BackoffLimitExceeded - the job pod waits for Autopilot to provision capacity,# which outlives the job's own deadline. cert-manager itself comes up fine.# Under Helm this marked the whole release failed; under Config Sync a hook job# would be applied as an ordinary Job and simply fail forever.enabled:falseimage:repository:asia-south1-docker.pkg.dev/saudi-prod-artifacts-0/shared-docker/cert-manager-startupapicheck
Top comments (0)
Subscribe
For further actions, you may consider blocking this person and/or reporting abuse
We're a place where coders share, stay up-to-date and grow their careers.
Top comments (0)