To use the HTTPS protocol, create a secret with a certificate. The setup consists of the following steps:
- Prepare a certificate.
- Create a secret with a certificate.
- Configure trust support on the HUMMIX app side, if this is required for the certificate or a set of CA certificates you are using.
Step 1: Prepare a certificate
The available certificate issuance methods depend on your installation environment:
- If you have internet access, you can:
- Purchase a certificate issued by one of the trusted certificate authorities, or use one you already have.
- Create a Let's Encrypt certificate.
- If you are working in a closed environment without internet access, you can:
- Use a certificate you already have that was issued by a local certificate authority.
- Create a self-signed certificate using OpenSSL.
- Create a self-signed certificate using Cert-manager.
Step 2: Create a secret with a certificate
Add the certificate to Kubernetes. To do this, in the namespace of the target application, create a secret of the TLS type named hummix-onpremise-tls by running the following command:
kubectl create secret tls hummix-onpremise-tls \
--cert=path/to/cert/file \
--key=path/to/key/file [-n namespace]
Where:
- --cert: the path to the public certificate file in .pem or .crt format.
- --key: the path to the private key file.
Note
Note
Create the secret with the certificate in the same namespace where the target application for which the certificate is issued works or will be installed:
- For the HUMMIX application, the standard namespace is hummix.
- For embedded databases, the standard namespace is hummix-dbs.
Step 3: Configure trust support for the root CA certificate
Perform this step in the following cases:
- The certificate is issued by a local certificate authority.
- You are using a self-signed certificate.
- You are using multiple CA certificates that require trust support to be configured.
Method 1: Configure trust support using the HUMMIX Helm chart
Use this method if trust support is only required for the HUMMIX application.
If you need to configure trust for several root or intermediate certificate authorities at once—for example, your company's local CA and the certificates from local authorities—first combine the certificates into a single file.
To configure trust support using the HUMMIX Helm chart, do the following:
- If you are using multiple CA certificates, combine them into a single file:
awk 1 local-ca.crt local_trusted_root_ca.crt local_trusted_sub_ca.crt > path/to/rootCA
- In the namespace where the HUMMIX application is installed, create a ConfigMap from the CA certificate file or the combined CA certificate file:
kubectl create configmap hummix-onpremise-ca \
--from-file=hummix-onpremise-ca.pem=path/to/rootCA [-n namespace]
- Open the configuration file values-hummix.yaml that you filled in during HUMMIX installation.
Attention
Before editing the file values-hummix.yaml, create a backup, since incorrect parameter configuration can cause the HUMMIX application to malfunction.
In the configuration file values-hummix.yaml, fill in the following parameters:
- global.ingress.onpremiseTls.enabledCA: whether the HUMMIX application uses a custom root CA certificate. To enable this parameter, set it to true.
- global.ingress.onpremiseTls.configCA: the name of the ConfigMap you created earlier. This article uses the name hummix-onpremise-ca.
Example file:
global:
...
ingress:
# Enable host in ingress (value taken from host)
# If S3 MinIO was installed using the hummix-dbs charts, in the values-dbs.yaml file
# in the minio block, specify the value in the hosts parameter
hostEnabled: false
onpremiseTls:
# enable HTTPS
enabled: true
# name of the secret with certificates for HTTPS
secret: "hummix-onpremise-tls"
# enable the root CA certificate for HTTPS with a self-signed certificate
enabledCA: true
# name of the ConfigMap with the root CA certificate for HTTPS with a self-signed certificate
configCA: "hummix-onpremise-ca"
- Apply the parameters you set. To learn more, see Enable network encryption (TLS) in HUMMIX On-Premises.
Method 2: Configure trust support using Kyverno
Use this method if trust support is required for both the HUMMIX application and the embedded databases at the same time. Kyverno lets you automatically add a volume containing custom CA certificates to containers with a specific label. To learn more, see Install Kyverno.