Explicitly point out not installing ns-cert component for http01 challenge (#2890)

* explicitly point out not installing ns-cert component for http01 challenge

* fix format

* address comments
This commit is contained in:
Zhimin Xiang 2020-10-12 05:46:16 -07:00 committed by GitHub
parent ccb8363b92
commit 0f436f9248
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 5 additions and 1 deletions

View File

@ -31,7 +31,8 @@ Knative supports the following Auto TLS modes:
- In this type, your cluster does not need to be able to talk to your DNS server. You just - In this type, your cluster does not need to be able to talk to your DNS server. You just
need to map your domain to the IP of the cluser ingress. need to map your domain to the IP of the cluser ingress.
- When using HTTP-01 challenge, **a certificate will be provisioned per Knative Service.** Certificate provision per namespace is not supported when using HTTP-01 challenge. - When using HTTP-01 challenge, **a certificate will be provisioned per Knative Service.**
- **HTTP-01 does not support provisioning a certificate per namespace.**
## Before you begin ## Before you begin
@ -154,6 +155,9 @@ and which DNS provider validates those requests.
If you choose to use the mode of provisioning certificate per namespace, you need to install `networking-ns-cert` components. If you choose to use the mode of provisioning certificate per namespace, you need to install `networking-ns-cert` components.
**IMPORTANT:** Provisioning a certificate per namespace only works with DNS-01
challenge. This component cannot be used with HTTP-01 challenge.
1. Determine if `networking-ns-cert` deployment is already installed by 1. Determine if `networking-ns-cert` deployment is already installed by
running the following command: running the following command: