fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

8.6K
active users

Mauricio Teixeira 🇺🇸🇧🇷<p>Sometimes I don't know if GatewayAPI is overkill for my home lab use, or if I'm just doing it wrong. The fact is that cert-manager acme http01 validation with http to https redirect is driving me crazy, and I can't figure out an easy way out.</p><p>Right now my gut is telling me to tear everything down and start over, because I feel like I did something wrong right at the initial deployment.</p><p>Yes, this post is vague on purpose, as I'm not ready to share my shame, I just need to vent. But if you do have a "this is the happy path" tutorial, I would not oppose to reading it.</p><p><a href="https://hachyderm.io/tags/HomeLab" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HomeLab</span></a> <a href="https://hachyderm.io/tags/GatewayAPI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GatewayAPI</span></a> <a href="https://hachyderm.io/tags/Kubernetes" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Kubernetes</span></a> <a href="https://hachyderm.io/tags/CertManager" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CertManager</span></a></p>
Janik :linux: :ansible: :bash:<p>I tinkered with <a href="https://fosstodon.org/tags/arm64" class="mention hashtag" rel="tag">#<span>arm64</span></a> <a href="https://fosstodon.org/tags/Docker" class="mention hashtag" rel="tag">#<span>Docker</span></a> <a href="https://fosstodon.org/tags/RaspberryPi" class="mention hashtag" rel="tag">#<span>RaspberryPi</span></a> <a href="https://fosstodon.org/tags/K3s" class="mention hashtag" rel="tag">#<span>K3s</span></a> <a href="https://fosstodon.org/tags/dyndns" class="mention hashtag" rel="tag">#<span>dyndns</span></a> <a href="https://fosstodon.org/tags/FritzBox" class="mention hashtag" rel="tag">#<span>FritzBox</span></a> <a href="https://fosstodon.org/tags/pironman5" class="mention hashtag" rel="tag">#<span>pironman5</span></a> <a href="https://fosstodon.org/tags/certmanager" class="mention hashtag" rel="tag">#<span>certmanager</span></a> <a href="https://fosstodon.org/tags/ingressnginx" class="mention hashtag" rel="tag">#<span>ingressnginx</span></a> and got this <a href="https://janikvonrotz.k3s.raspberrypi.build/" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="ellipsis">janikvonrotz.k3s.raspberrypi.b</span><span class="invisible">uild/</span></a> running :coolmsn:</p>
Daniel S. Reichenbach<p>A lesson learned for <a href="https://mastodon.world/tags/cilium" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cilium</span></a> and <a href="https://mastodon.world/tags/certmanager" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>certmanager</span></a> on <a href="https://mastodon.world/tags/kubernetes" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>kubernetes</span></a> </p><p>One shall never forget all necessary http routes and most importantly the enableGatewayAPI flag.</p><p>This one also helped: <a href="https://kubito.dev/posts/gateway-api-cert-manager/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">kubito.dev/posts/gateway-api-c</span><span class="invisible">ert-manager/</span></a></p>
Yorgos Saslis<p>It is now already Tuesday morning but everything is back online.</p><p>✅ <a href="https://chaos.social/tags/Pihole" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Pihole</span></a> is back up so <a href="https://chaos.social/tags/DNS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DNS</span></a> resolution works again and the rest of the family can use the internet! <br>✅ NFS provisioners can provide persistent volumes, <br>✅ <a href="https://chaos.social/tags/CertManager" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CertManager</span></a> issues HTTPS certificates,<br>✅ <a href="https://chaos.social/tags/Unifi" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Unifi</span></a> controller is back up to allow me to actually make changes to my network config (such as, say, change DNS settings when pihole is down... ) <br>✅ <a href="https://chaos.social/tags/HomeAssistant" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HomeAssistant</span></a> automates away,<br>✅ <a href="https://chaos.social/tags/Nextcloud" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Nextcloud</span></a> is seeing sunnier days, <br>✅ <a href="https://chaos.social/tags/Photoprism" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Photoprism</span></a> &lt;3</p>
Yorgos Saslis<p>When <a href="https://chaos.social/tags/certManager" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>certManager</span></a> works, it's beautiful. It'd been working smoothly for YEARS without me needing to touch it. </p><p>Getting it to work though... !?</p><p>Well, let's just I'd forgotten how much "fun" that can be.</p>

I'm going to be at . At the maintainers summit beforehand, at the contribfest, and at the project pavilion.

Contribfest session: kccnceu2025.sched.com/event/1t

I'm looking forward to connecting with folks working on different projects. People have been quite busy building out Headlamp Kubernetes UIs for ecosystem tooling and standards like and

kccnceu2025.sched.comKubeCon + CloudNativeCon Europe 2025: 🚨 Contribfest: Make Your Own UI for Kube...View more about this event at KubeCon + CloudNativeCon Europe 2025

💻🧾 An alle #CertManager Profis:

Lassen sich mit der DNS-Challenge und #Webhook auf einem anderen Server, als auf dem die #Domain und Website gehostet ist, #Zertifikate für die Hauptdomain wie z.B. meinedomain.de erzeugen?

Hintergrund: mein #ejabberd läuft bei mir zuhause auf meiner Hauptdomain, für mein Domain-/Webhoster gibts aber keinen Webhook... Daher erwäge ich zu wechseln falls das möglich wäre...

Evtl. kann auch @CertManager, @netcup oder @team was dazu sagen 🤔

🔃🙏

So I've managed to finally get #Traefik working with #CertManager.

It took lots of frustration, a sidequest around attempting replace Traefik with the #Cilium Gateway API implementation, to lots of annoyance and frustration, broken iptables, but we finally got back to pretty much where we started and things started to fall in place from here.

So the good news is by separating certificates from Traefik, we can now get Traefik doing HA. Why you ask? Just cause.

I had the rare opportunity to need to send a physical mail, a form. There used to be a SAM machine near my place where you can print out a stamp but they removed it recently.

I search for the nearest SAM machines near me, Google Maps showed the nearest one and along with the business info, included is the URL mysam.sg.

#singpost#mysam#tls
404Not Found