Issuer) and cluster-scoped (ClusterIssuer) resources.
For more information on Infisical PKI, see the PKI documentation.
Installation
1
Install cert-manager (if not already installed)
2
Install the Infisical PKI Issuer
3
Verify the deployment
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Deploy the Infisical PKI Issuer for cert-manager on Kubernetes using the official Helm chart.
Issuer) and cluster-scoped (ClusterIssuer) resources.
For more information on Infisical PKI, see the PKI documentation.
Install cert-manager (if not already installed)
helm repo add jetstack https://charts.jetstack.io
helm repo update
helm install cert-manager jetstack/cert-manager \
--namespace cert-manager \
--create-namespace \
--set crds.enabled=true
Install the Infisical PKI Issuer
helm install infisical-pki-issuer \
oci://helm.oci.cloudsmith.io/infisical/helm-charts/infisical-pki-issuer \
--namespace infisical-pki \
--create-namespace
Verify the deployment
kubectl get pods -n infisical-pki
helm uninstall infisical-pki-issuer --namespace infisical-pki
| Parameter | Default | Description |
|---|---|---|
controllerManager.replicas | 1 | Number of controller replicas. |
controllerManager.manager.image.repository | docker.io/infisical/pki-issuer | Container image. |
controllerManager.manager.image.tag | latest | Image tag. |
controllerManager.manager.resources.requests.cpu | 10m | CPU request. |
controllerManager.manager.resources.requests.memory | 64Mi | Memory request. |
controllerManager.manager.resources.limits.cpu | 500m | CPU limit. |
controllerManager.manager.resources.limits.memory | 128Mi | Memory limit. |
controllerManager.serviceAccount.annotations | {} | Service account annotations. |
controllerManager:
manager:
args:
- --metrics-bind-address=:8443
- --leader-elect
- --health-probe-bind-address=:8081
containerSecurityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
image:
repository: docker.io/infisical/pki-issuer
tag: latest
resources:
limits:
cpu: 500m
memory: 128Mi
requests:
cpu: 10m
memory: 64Mi
podSecurityContext:
runAsNonRoot: true
replicas: 1
serviceAccount:
annotations: {}
controllerMetrics:
ports:
- name: https
port: 8443
protocol: TCP
targetPort: 8443
type: ClusterIP
kubernetesClusterDomain: cluster.local
Was this page helpful?