ingress
ingress copied to clipboard
Add zerossl issuer
We currently only support acme issuer, we should add support for zerossl
There was work at my org to add this functionality to the ingress controller and we successfully updated to leverage zerossl as an issuer. I can create a pull-request with this work, and it can be validated if its current shape is something this project finds value in, or if we need to change something.
Yes, I've grown to prefer ZeroSSL personally, after having had multiple bugs in my attempted integration of Let's Encrypt with Kubernetes that ended up exhausting my certificate-provisioning quota. (the old ones were lost in the development/debugging process...)
I would have been happy to pay some to get past the quota-limit that time, but LE does not offer that option; that made me nervous, realizing that if a mistake like that happened again in the future, it could cause a serious problem if it happens at a key point, and there is not time to switch to a completely new certificate-provider.
My domain is a .app domain, which cannot even be served from without a valid TLS, so if your certificate story is broken your site invariably goes down; being able to pay for unlimited certificates in the event of an emergency is thus a big advantage, in my view. (which zerossl provides)
PR #101 brings ZeroSSL support through EAB credentials 🎉 so I'm gonna close this as completed.
Note that it would be nice to support ZeroSSL issuer directly through their API. If this is something people want, feel free to open a PR/issue 😃