Configuring the egress proxy for the cert-manager Operator for Red Hat OpenShift¶
If a cluster-wide egress proxy is configured in OpenShift Container Platform, Operator Lifecycle Manager (OLM) automatically configures Operators that it manages with the cluster-wide proxy. OLM automatically updates all of the Operator’s deployments with the HTTP_PROXY, HTTPS_PROXY, NO_PROXY environment variables.
You can inject any CA certificates that are required for proxying HTTPS connections into the cert-manager Operator for Red Hat OpenShift.
Injecting a custom CA certificate for the cert-manager Operator for Red Hat OpenShift¶
If your OpenShift Container Platform cluster has the cluster-wide proxy enabled, you can inject any CA certificates that are required for proxying HTTPS connections into the cert-manager Operator for Red Hat OpenShift.
Prerequisites
- You have access to the cluster as a user with the
cluster-adminrole. - You have enabled the cluster-wide proxy for OpenShift Container Platform.
Procedure
-
Create a config map in the
cert-managernamespace by running the following command: -
Inject the CA bundle that is trusted by OpenShift Container Platform into the config map by running the following command:
-
Update the deployment for the cert-manager Operator for Red Hat OpenShift to use the config map by running the following command:
Verification
-
Verify that the deployments have finished rolling out by running the following command:
$ oc rollout status deployment/cert-manager-operator-controller-manager -n cert-manager-operator && \ oc rollout status deployment/cert-manager -n cert-manager && \ oc rollout status deployment/cert-manager-webhook -n cert-manager && \ oc rollout status deployment/cert-manager-cainjector -n cert-manager -
Verify that the CA bundle was mounted as a volume by running the following command:
-
Verify that the source of the CA bundle is the
trusted-caconfig map by running the following command:
Additional resources