# Rancher 2 and Letsencrypt

**URL:** <https://forums.suse.com/t/rancher-2-and-letsencrypt/10492>\
**Category:** SUSE Rancher Prime\
**Created:** [May 21, 2018, 11:12am UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492 "2018-05-21T11:12:12Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dremor](https://avatars.discourse-cdn.com/v4/letter/d/ed655f/32.png) [@Dremor](https://forums.suse.com/u/Dremor)\
**Post date:** [May 21, 2018, 11:12am UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/1 "2018-05-21T11:12:12Z")

</div>

Hi,

I’m considering switching from Rancher 1.6 to Rancher 2.0, but there is still some part I’m unable to migrate, the main one being my Letencrypt certificate.

On Rancher 1.6, I’m using the Let’s Encrypt stack in the catalogue ([https://github.com/janeczku/rancher-letsencrypt](https://github.com/janeczku/rancher-letsencrypt)), but there is no Rancher 2 version yet, and the author said that he won’t port it.

Is there an alternative for Rancher 2, and if so, how to configure it with Rancher 2 ?

---

<div class="post-metadata">

**Author:** ![josmo](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/josmo/32/3651_2.png) [@josmo](https://forums.suse.com/u/josmo)\
**Post date:** [May 25, 2018, 11:30pm UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/2 "2018-05-25T23:30:22Z")

</div>

Check out the cert-manager in the catalog. It’s a helm chart for doing exactly that 🙂

---

<div class="post-metadata">

**Author:** ![josmo](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/josmo/32/3651_2.png) [@josmo](https://forums.suse.com/u/josmo)\
**Post date:** [May 27, 2018, 7:41pm UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/3 "2018-05-27T19:41:24Z")

</div>

Check out this post. It probably has most of the info you might need 🙂 [Cert-manager and Rancher 2.0?](http://forums.suse.com/t/cert-manager-and-rancher-2-0/10361/6)

---

<div class="post-metadata">

**Author:** ![lgatica](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/lgatica/32/3570_2.png) [@lgatica](https://forums.suse.com/u/lgatica)\
**Post date:** [May 30, 2018, 1:19am UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/4 "2018-05-30T01:19:36Z")

</div>

Hi, I just installed cert-manager, but I do not know what else to do to add certificates. There is a tutorial to review.

---

<div class="post-metadata">

**Author:** ![dhawton](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/dhawton/32/4131_2.png) [@dhawton](https://forums.suse.com/u/dhawton)\
**Post date:** [June 3, 2018, 12:07pm UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/5 "2018-06-03T12:07:13Z")

</div>

I’ve created a video tutorial on setting up and using cert-manager with Rancher’s nginx ingresses as well. [https://www.youtube.com/watch?v=xc8Jg9ItDVk](https://www.youtube.com/watch?v=xc8Jg9ItDVk) hopefully this helps you

---

<div class="post-metadata">

**Author:** ![Dremor](https://avatars.discourse-cdn.com/v4/letter/d/ed655f/32.png) [@Dremor](https://forums.suse.com/u/Dremor)\
**Post date:** [June 3, 2018, 8:19pm UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/6 "2018-06-03T20:19:02Z")

</div>

Very interesting video. I would be great to have a Helm chart helping doing this. I’ll try to do it, as it would be a good way to learn to do a Rancher Helm Chart.

---

<div class="post-metadata">

**Author:** ![dhawton](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/dhawton/32/4131_2.png) [@dhawton](https://forums.suse.com/u/dhawton)\
**Post date:** [June 3, 2018, 11:05pm UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/7 "2018-06-03T23:05:50Z")

</div>

Just trying to help. I struggled with it for a bit, and once I got it sorted wanted to show others since I’ve seen the question asked several times.

---

<div class="post-metadata">

**Author:** ![etlweather](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/etlweather/32/419_2.png) [@etlweather](https://forums.suse.com/u/etlweather)\
**Post date:** [June 4, 2018, 3:41pm UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/8 "2018-06-04T15:41:21Z")

</div>

Thanks for the video.

Do you know, if on wildcard certificates, you have to specify every hosts in the TLS section? I’m struggling a bit with this.

[http://forums.suse.com/t/ingress-tls-with-wildcard-cert](http://forums.suse.com/t/ingress-tls-with-wildcard-cert)

---

<div class="post-metadata">

**Author:** ![dhawton](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/dhawton/32/4131_2.png) [@dhawton](https://forums.suse.com/u/dhawton)\
**Post date:** [June 4, 2018, 6:32pm UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/9 "2018-06-04T18:32:31Z")

</div>

Glad to help.

My understanding is, according to [https://github.com/kubernetes/ingress-nginx/issues/8](https://github.com/kubernetes/ingress-nginx/issues/8), that you can use \*.example.com in the hosts field.

To use it, I had to define the rule with the wildcard. The hostname in the rule must also match the hostname in the TLS config.

Here’s the YAML of what I have working on my setup.

```
spec:
  rules:
  - host: example.com
    http:
      paths:
      - backend:
          serviceName: ingress-89d08e42f206c06d886aeab617ea1b7f
          servicePort: 80
  - host: '*.example.com'
    http:
      paths:
      - backend:
          serviceName: ingress-ee03ffca50ad2849920b3ad055609f1d
          servicePort: 80
  tls:
  - hosts:
    - example.com
    - '*.example.com'
    secretName: example-com-tls
```

---

<div class="post-metadata">

**Author:** ![chris.ingenhaag](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/chris.ingenhaag/32/5703_2.png) [@chris.ingenhaag](https://forums.suse.com/u/chris.ingenhaag)\
**Post date:** [June 5, 2018, 6:08am UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/10 "2018-06-05T06:08:21Z")

</div>

Hi @dhawton,  
thx for your video. When following the tasks in the video creating Issuer and ClusterIssuer seems to work fine. But when I try to describe them I get a NotFound message from Rancher.

I´m working with a single node (server + node on one machine) in my case (server v2.0.2). Is there anybody else who has this behavior?

regards

---

<div class="post-metadata">

**Author:** ![dhawton](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/dhawton/32/4131_2.png) [@dhawton](https://forums.suse.com/u/dhawton)\
**Post date:** [June 5, 2018, 7:45am UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/11 "2018-06-05T07:45:36Z")

</div>

@chris.ingenhaag

Are you checking the correct namespace?

IE, if your Issuer and Certificate are not in default, you would need to add --namespace=(namespace) to the kubectl command to make sure it’s checking there (otherwise it looks at default).

If you’re doing a bunch of commands in the same namespace, you can change your current context [https://kubernetes.io/docs/tasks/administer-cluster/namespaces-walkthrough/](https://kubernetes.io/docs/tasks/administer-cluster/namespaces-walkthrough/) by doing:

```
kubectl config use-context (namespace name)

```

Hope that is what’s doing it.

---

<div class="post-metadata">

**Author:** ![chris.ingenhaag](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/chris.ingenhaag/32/5703_2.png) [@chris.ingenhaag](https://forums.suse.com/u/chris.ingenhaag)\
**Post date:** [June 6, 2018, 10:45am UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/12 "2018-06-06T10:45:55Z")

</div>

Thanks for the hint _facepalm_. Got it working now.

---

<div class="post-metadata">

**Author:** ![Dremor](https://avatars.discourse-cdn.com/v4/letter/d/ed655f/32.png) [@Dremor](https://forums.suse.com/u/Dremor)\
**Post date:** [June 6, 2018, 11:12am UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/13 "2018-06-06T11:12:24Z")

</div>

Yay ! Made it work. Now I’ve an HTTPS Rocket.Chat instance working. 🙂

---

<div class="post-metadata">

**Author:** ![jkmuk](https://avatars.discourse-cdn.com/v4/letter/j/c37758/32.png) [@jkmuk](https://forums.suse.com/u/jkmuk)\
**Post date:** [June 6, 2018, 8:02pm UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/14 "2018-06-06T20:02:21Z")

</div>

Hi,  
Should the DNS01 provider be supported on certmanager specifically? E.g. I am trying to use GoDaddy which is supported by acme, but it is not listed on the certmanager link

---

<div class="post-metadata">

**Author:** ![dhawton](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/dhawton/32/4131_2.png) [@dhawton](https://forums.suse.com/u/dhawton)\
**Post date:** [June 6, 2018, 8:31pm UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/15 "2018-06-06T20:31:44Z")

</div>

Yes, it must be supported by cert-manager as it’s cert manager that puts in the TXT NS records. Let’s encrypt supports all dns providers as it only makes requests.

---

<div class="post-metadata">

**Author:** ![spatialy](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/spatialy/32/2664_2.png) [@spatialy](https://forums.suse.com/u/spatialy)\
**Post date:** [July 12, 2018, 4:27pm UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/16 "2018-07-12T16:27:06Z")

</div>

Hi all

I have a weird situation: follow the guide and the video and get able to create a ClusterIssuer and a Certificate for a given namespace, the certificate is added to the secret and showed in the ingress controller but the site continue to be served over http by the default ingress.local certificate.

Any help?

Thanks in advance

Yulian

---

<div class="post-metadata">

**Author:** ![dhawton](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/dhawton/32/4131_2.png) [@dhawton](https://forums.suse.com/u/dhawton)\
**Post date:** [July 12, 2018, 5:16pm UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/17 "2018-07-12T17:16:59Z")

</div>

Generally that happens when the certificate doesn’t match the host for the site requested. If the ingress can’t find a certificate, it serves the default. Try readding the ingress and checking the certificate request thoroughly.

---

<div class="post-metadata">

**Author:** ![spatialy](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/spatialy/32/2664_2.png) [@spatialy](https://forums.suse.com/u/spatialy)\
**Post date:** [July 12, 2018, 6:44pm UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/18 "2018-07-12T18:44:30Z")

</div>

Hi @dhawton, thanks for the response

Can you help me on how to read the ingress to debug the problem, I am starting my steps with kubernetes.

Thanks

Yulian

---

<div class="post-metadata">

**Author:** ![gadicc](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/gadicc/32/4268_2.png) [@gadicc](https://forums.suse.com/u/gadicc)\
**Post date:** [July 17, 2018, 3:09pm UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/19 "2018-07-17T15:09:22Z")

</div>

@dhawton, just another massive thanks for your video. I’m new to rancher and k8s, and was totally overwhelmed trying to get this working until I came across this thread. Thanks so much for going over everything in such detail (especially things like pointing out that cert-manager certs look “broken” in rancher). I now understand really well how all these different parts work and really want to thank you for all the time and thought you put into the video.

Also, in case it helps others, for whatever reason, when editing my ingress, in the “SSL” section, it always said “No certificates”. But when creating a new ingress, the certificate I’d created showed up… so I just deleted the old ingress, created a new one, and everything works perfectly (yay, my PWA finally has offline support :)).

---

<div class="post-metadata">

**Author:** ![chris.ingenhaag](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/chris.ingenhaag/32/5703_2.png) [@chris.ingenhaag](https://forums.suse.com/u/chris.ingenhaag)\
**Post date:** [July 19, 2018, 9:13am UTC](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492/20 "2018-07-19T09:13:07Z")

</div>

After the manual creation of an certificate now is working for me also with a help from @dhawton ´s video, I tried to get automated annotation-based creation of the certificates working. But there I run into several problems. I tried with helm-stable cert-manager and now also with the cert-manager available in rancher-library.

Does anybody have a working annotation combination which automatically creates a certificate and assigns it to a existing ingress? [https://cert-manager.readthedocs.io/en/latest/reference/ingress-shim.html](https://cert-manager.readthedocs.io/en/latest/reference/ingress-shim.html)

My status is that I either get information that ingress will not be processed from certmanager because it doesn´t have necessary annotations or that certmanager cannot find “” issuer.

regards, Christian

[Next page](https://forums.suse.com/t/rancher-2-and-letsencrypt/10492.md?page=2)
