Docs › Certificates
Wildcard certificates with cert-manager (Kubernetes)
Store the credential JSON in a Secret, then reference it from the acmeDNS solver.
Where the configuration lives
Issuer or ClusterIssuer
Configuration
ClusterIssuer
solvers:
- dns01:
acmeDNS:
host: https://api.home.network/acmedns
accountSecretRef:
name: acme-dns-creds
key: acmedns.json
# kubectl create secret generic acme-dns-creds --from-literal=acmedns.json='
# {"alice.home.network":{"username":"<your username>",
# "password":"<your key>","fulldomain":"_acme-challenge.alice.home.network",
# "subdomain":"<your subdomain>","allowfrom":[]}}'The username, password and subdomain come from the setup wizard, which shows them once. They are stored hashed, so a lost set is replaced rather than recovered.
Worth knowing. The Secret key name must match key
exactly, and the JSON is the same shape as the other clients use.
Ask for both names
A wildcard does not cover the name it sits under, so a certificate for *.alice.home.network alone leaves alice.home.network without one. Request both in a single certificate.
Check it worked
verify
# the challenge value your client published
dig +short TXT _acme-challenge.alice.home.network @ns1.home.network
# what the certificate ended up covering
echo | openssl s_client -servername nas.alice.home.network \
-connect nas.alice.home.network:443 2>/dev/null \
| openssl x509 -noout -text | grep -A1 "Subject Alternative Name"Why only wildcards
Challenge records are writable only at your label apex, so the only certificates obtainable are the wildcard and the label itself. Your individual device names never reach Certificate Transparency logs, which is a consequence of the design rather than a setting to remember.