k8s webhook error(remote error: tls: bad certificate ) reason

Viewed 62

When I use the following helm configuration to generate a certificate and act on the webhook, I get an error remote error: tls: bad certificate in k8s v1.22, but it can work in 1.18.20. It seems to be a certificate error

# generate the certs
{{- if .Values.mutatingWebhook.enabled }}
{{- $cn := printf "%s.%s.svc" ( include "mutate.service.name" . ) .Release.Namespace }}
{{- $ca := genCA "mutate-admission-ca" 36500 -}}
{{- $cert := genSignedCert $cn nil nil 36500 $ca -}}

I hope it can work on multiple versions, I achieved the adaptation in these two versions by modifying as follows

# generate the certs
{{- if .Values.mutatingWebhook.enabled }}
{{- $name := printf "%s" (include "podinjector.service.name" .) }}
{{- $cn:= list ( printf "%s.%s" $name .Release.Namespace ) ( printf "%s.%s.svc" $name .Release.Namespace ) ( printf "%s.%s.svc.cluster.local" $name .Release.Namespace ) }}
{{- $ca := genCA "podinjector-admission-ca" 36500 -}}
{{- $cert := genSignedCert $name nil $cn 36500 $ca -}}

This just adds two subjectAltNames

I would like to know why there is such a difference, is this version with minor changes to compatibility?

Looking forward to your reply

0 Answers
Related