okustera_gateway_certificate (Resource)
Provisions and manages automated TLS/SSL certificates issued via Let's Encrypt ACME or an internal enterprise Certificate Authority (CA) through cert-manager. Certificates can be bound to APISIX Ingress Gateway routes.
Example Usage
Automated Let's Encrypt TLS Certificate
resource "okustera_gateway_certificate" "api_cert" {
domain = "api.example.com"
issuer = "letsencrypt-prod"
auto_renew = true
secret_name = "api-example-tls"
}
resource "okustera_apisix_route" "api_route" {
name = "public-api"
domain = okustera_gateway_certificate.api_cert.domain
path = "/api/*"
service_name = "api-backend-svc"
service_port = 8080
target_namespace = "production"
tls_enabled = true
cluster_issuer = okustera_gateway_certificate.api_cert.issuer
}
Schema
Required
domain(String, Forces new resource) Fully qualified domain name (FQDN) or wildcard pattern for the certificate.
Optional
auto_renew(Boolean) Whether to enable automatic certificate rotation and renewal prior to expiry. Defaults totrue.issuer(String) Certificate issuer or cert-manager ClusterIssuer (e.g.letsencrypt-prod,letsencrypt-staging,selfsigned). Defaults toletsencrypt-prod.secret_name(String) Name of the Kubernetes Secret where certificate and private key will be stored. Defaults to<domain>-tls.
Read-Only
created_at(String) Timestamp when certificate was registered.id(String) Unique certificate identifier ID.status(String) Issuance state (e.g.Ready,Pending,Expired).updated_at(String) Timestamp when certificate status was last evaluated.valid_until(String) Expiration date of the current active certificate.
Import
Certificates can be imported using the numeric certificate id:
terraform import okustera_gateway_certificate.example 42