#!/usr/bin/env bash # Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. # SPDX-License-Identifier: Apache-2.0 set -euo pipefail # Install and configure cert-manager to generate letsencrypt TLS certs for the supervisor # which can be used for manual testing on the cluster. In order to use it, create a # FederationDomain which specifies an issuer with the same name DNS name as the certificate # and also specifies the same secretName as used below in the Certificate CR. # The DNS record for the DNS name use here should be manually created elsewhere to point # to the Supervisor's load balancer IP address. # # See sample-federation-domain.yaml in this directory for an example FederationDomain # which will use these letsencrypt certs, which you can apply to the acceptance cluster. if [[ -z "${PINNIPED_GCP_PROJECT:-}" ]]; then echo "PINNIPED_GCP_PROJECT env var must be set" exit 1 fi # Use the kubeconfig from the task inputs. export KUBECONFIG="$(pwd)/kubeconfig/kubeconfig" # Load some deployment related env vars, like PINNIPED_TEST_SUPERVISOR_NAMESPACE, from the task inputs. source integration-test-env-vars/integration-test-env # Install or update cert-manager. This will create a "cert-manager" namespace. kapp deploy --yes --app cert-manager --diff-changes \ --file "https://github.com/cert-manager/cert-manager/releases/download/v1.10.1/cert-manager.yaml" # Configure a DNS admin account for cert-manager to use. cat <