cert-manager
Public ACME issuers and an internal certificate authority.
This directory contains chart values and issuer resources, not the controller
installation. Install the cert-manager chart with CRDs and the settings in
k8s/cert-manager-values.yaml before applying the issuers.
clusterissuer.yaml defines staging and production Let's Encrypt issuers.
They use HTTP-01 through the Traefik ingress class. Public DNS and inbound HTTP
reachability must work for the requested names before issuance.
internal-ca.yaml bootstraps the internal CA. Keep its private-key Secret backed
up; the tracked .crt is only a public certificate.
This directory has no k8s/active marker. Apply the issuer files deliberately;
kubectl apply does not interpret the Helm values file.
See the repository README for deployment selection.