ingress icon indicating copy to clipboard operation
ingress copied to clipboard

Add zerossl issuer

Open Embraser01 opened this issue 3 years ago • 2 comments

We currently only support acme issuer, we should add support for zerossl

Embraser01 avatar Apr 14 '22 10:04 Embraser01

There was work at my org to add this functionality to the ingress controller and we successfully updated to leverage zerossl as an issuer. I can create a pull-request with this work, and it can be validated if its current shape is something this project finds value in, or if we need to change something.

mikemimik avatar May 10 '22 22:05 mikemimik

Yes, I've grown to prefer ZeroSSL personally, after having had multiple bugs in my attempted integration of Let's Encrypt with Kubernetes that ended up exhausting my certificate-provisioning quota. (the old ones were lost in the development/debugging process...)

I would have been happy to pay some to get past the quota-limit that time, but LE does not offer that option; that made me nervous, realizing that if a mistake like that happened again in the future, it could cause a serious problem if it happens at a key point, and there is not time to switch to a completely new certificate-provider.

My domain is a .app domain, which cannot even be served from without a valid TLS, so if your certificate story is broken your site invariably goes down; being able to pay for unlimited certificates in the event of an emergency is thus a big advantage, in my view. (which zerossl provides)

Venryx avatar Jul 02 '22 16:07 Venryx

PR #101 brings ZeroSSL support through EAB credentials 🎉 so I'm gonna close this as completed.

Note that it would be nice to support ZeroSSL issuer directly through their API. If this is something people want, feel free to open a PR/issue 😃

Embraser01 avatar Aug 22 '22 10:08 Embraser01