Skip to main content

okustera_gateway_certificate (Resource)

Provisions and manages automated TLS/SSL certificates issued via Let's Encrypt ACME or an internal enterprise Certificate Authority (CA) through cert-manager. Certificates can be bound to APISIX Ingress Gateway routes.

Example Usage​

Automated Let's Encrypt TLS Certificate​

resource "okustera_gateway_certificate" "api_cert" {
domain = "api.example.com"
issuer = "letsencrypt-prod"
auto_renew = true
secret_name = "api-example-tls"
}

resource "okustera_apisix_route" "api_route" {
name = "public-api"
domain = okustera_gateway_certificate.api_cert.domain
path = "/api/*"
service_name = "api-backend-svc"
service_port = 8080
target_namespace = "production"
tls_enabled = true
cluster_issuer = okustera_gateway_certificate.api_cert.issuer
}

Schema​

Required​

  • domain (String, Forces new resource) Fully qualified domain name (FQDN) or wildcard pattern for the certificate.

Optional​

  • auto_renew (Boolean) Whether to enable automatic certificate rotation and renewal prior to expiry. Defaults to true.
  • issuer (String) Certificate issuer or cert-manager ClusterIssuer (e.g. letsencrypt-prod, letsencrypt-staging, selfsigned). Defaults to letsencrypt-prod.
  • secret_name (String) Name of the Kubernetes Secret where certificate and private key will be stored. Defaults to <domain>-tls.

Read-Only​

  • created_at (String) Timestamp when certificate was registered.
  • id (String) Unique certificate identifier ID.
  • status (String) Issuance state (e.g. Ready, Pending, Expired).
  • updated_at (String) Timestamp when certificate status was last evaluated.
  • valid_until (String) Expiration date of the current active certificate.

Import​

Certificates can be imported using the numeric certificate id:

terraform import okustera_gateway_certificate.example 42