Replies: 1 comment
-
Hi, I noticed that this exact issue was also mentioned in other places:
What was the name of the namespace you deleted? When you re-installed cert-manager, what was the new namespace name? The above deployment doesn't seem to have a namespace, does it indicate that the new namespace is I wrote about that kind of issue in https://cert-manager.io/docs/troubleshooting/webhook/#error-x509-certificate-signed-by-unknown-authority, but I am unsure whether that guide will help you. The error message comes from Could you try running with |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello,
I happened by mistake to delete the namespace where cert-manager runs and when redeploying the same configuration as before(static manifests with kustomize), webhook is up and running but when checking the logs I have this error:
E0125 11:55:01.878707 1 dynamic_source.go:85] cert-manager/webhook "msg"="Failed to generate initial serving certificate, retrying..." "error"="failed verifying CA keypair: tls: failed to find any PEM data in certificate input" "interval"=1000000000
This is the webhook deployment:
I believe with the flags configured, a secret "cert-manager-webhook-tls" should be automatically generated but it's not..
(I commented the Probe as the health check failed and I coudn't identify the correct port yet).
Environment:
Cert-manager : v1.10.0
Kubernetes: 1.21.14-gke.4300
Beta Was this translation helpful? Give feedback.
All reactions