In some cases, it is necessary to trust user-generated CA certificates. Kyverno allows you to automatically add a volume containing user CA certificates to containers with a specific label.
The installation consists of two stages:
Step 1: Prepare a Secret with a root CA certificate
Create a Secret with the root CA certificate in namespace where the HUMMIX application is installed. If there are multiple instances of HUMMIX installed in the Kubernetes cluster, add the Secret only to the namespace of the necessary instances of HUMMIX.
Create a Secret named hummix-onpremise-ca in the namespace where HUMMIX is installed by running the following command:
kubectl create secret generic hummix-onpremise-ca --from-file=hummix-onpremise-ca.pem=/etc/ssl/certs/rootCA.pem [-n namespace]
Where --from-file specifies the path to your root CA certificate in .pem format.
Step 2: Fill in the configuration file
Fill in the configuration file values-kyverno.yaml for setting up Kyverno:
- Configure the policy to add user CA certificates to all containers. The policy is enabled by default, the
kyverno.injectCerts.enabledparameter is set totrue. - In the
kyverno.injectCerts.secretCAparameter, specify the name of the Secret created in Step 1. In the example in this article, it ishummix-onpremise-ca. The policy adds a volume containing the CA certificate to all containers with the labeltier=hummix. - If there are multiple instances of the HUMMIX On-Premises application installed in the Kubernetes cluster, but the user CA certificate needs to be added only to some instances of the HUMMIX applications, fill in the
kyverno.injectCerts.injectNamespaceparameter.
In the kyverno.injectCerts.injectNamespace parameter, specify the namespaces of HUMMIX instances to which the policy of adding certificates will be applied and a volume containing the CA certificate will be added. Ensure that in Step 1, the Secret with the root CA certificate was added to the namespaces listed in kyverno.injectNamespace.
- Specify the
namespacefor the Kyverno service, in this article, it iskyverno. To ensure high availability, set the required number of replicas in thekyverno.injectCerts.injectNamespaceparameter.
# kyverno settings
kyverno:
# the policy adds the volume containing the CA certificate to all the containers labeled tier=hummix
injectCerts:
enabled: true
# name of the secret with the CA root certificate for https with a self-signed certificate
secretCA: hummix-onpremise-ca
# list of namespaces where the policy will be applied
# injectNamespace:
# - hummix-dev
# - hummix-prod
# namespace for kyverno (before installation, create kubectl create ns kyverno)
namespace: kyverno
# number of replicas for high availability
replicaCount: 1
# Install crds (not required, is added to directory crds)
installCRDs: false
...
# kyverno settings
|
Attention
Installing the Kyverno add-on component does not automatically connect the volume containing the CA certificate to the already running pods of the HUMMIX application. After installing Kyverno, restart the HUMMIX application services.