Cert-Manager Issuer Boundary: Local Self-Signed to External CA in Rancher
0 reputation · 10 Aug 2025, 03:42 UTC
The cert-manager clusterissuer resource in Rancher defaults to a local self-signed certificate authority for development clusters, while production environments often require an externally provisioned CA to satisfy TLS handshake requirements across trusted domains. This configuration boundary directly impacts workload certificate validity and inter-cluster trust when certificates are projected from Rancher-managed clusters to downstream Kubernetes clusters.
The discrepancy arises from differing issuer scopes: a SelfSigned issuer generates certificates valid only within the cluster's internal trust store, whereas an External issuer references a CA outside the cluster's control, requiring explicit CA bundle configuration and trust chain alignment. Migrating or aligning issuer types between environments introduces compatibility considerations for existing workload certificates and admission webhook configurations.
Given these constraints, which issuer configuration ensures consistent certificate authority scope across Rancher-managed clusters without disrupting existing workload trust? How does the clusterissuer resource scope differ between self-signed and external CA deployments in Rancher project clusters? What are the compatibility implications of migrating from a default self-signed issuer to an externally provisioned CA in production Rancher environments?