website icon indicating copy to clipboard operation
website copied to clipboard

Add a diagram for LetsEncrypt cert issuance flow to the docs

Open irbekrm opened this issue 4 years ago • 1 comments

I did some work diagramming cert-manager ACME cert issuance here https://miro.com/app/board/o9J_lUdPqQI=/

This is still somewhat unfinished, but we could try to merge some of this into cert-manager docs.

See a related Slack discussion https://kubernetes.slack.com/archives/C4NV3DWUC/p1621619947053400

irbekrm avatar May 21 '21 19:05 irbekrm

I genuinely feel that both the workflow sequence in the miro link above, as well as a diagrammatic workflow laying out that sequence, are desperately needed, as the workflow diagram offered on the homepage offers very little relevant detail to what actually occurs in the "life of a secret" within cert-manager. In other words: having a diagram that lays out how a certificate crd and a clusterissuer crd culminate in an ACME challenge being passed and an actual secret being created is so important because imo this workflow is understood from a general cryptographical standpoint by virtually no one, whether cert manager-related or not. I can only speak for myself, but having spent some serious amount of time reading the cert-manager documentation it definitely was not at all clear to me how yaml becomes actual secrets. This effort doesn't need to be perfect; something/anything would exponentially be more beneficial than nothing. Thank you!

jonassteinberg1 avatar May 21 '21 19:05 jonassteinberg1