[2.9] feat(helm-letsencrypt): adding dns01 challenge types to letsencrypt #45364
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Adding dns01 open-ended config to the helm-charts to allow systems that cant do port 80 challenges with letsenrypt.
Allows agnostic accepting of dns01 challenge types to include support for route53/azuredns/etc
Problem
Many environments are locking down port 80 communication. These environments may not have proxies, but it means it limits the ability to use the LetsEncrypt Cert Manager to create the certs because we have only http01 hardcoded and cant use more flexibly acceptable challenge types like dns01 which has more cloud specific support
Solution
Add support for dns01 challenge type (still defaults to http01 for behavior consistency) which will then inject the provided values configuration to support any type of sub dns01 challenge