# Finally, generate a serving certificate for the webhook to use apiVersion: certmanager.k8s.io/v1alpha1 kind: Certificate metadata: name: cert-manager-webhook-webhook-tls namespace: "cert-manager" labels: app: webhook app.kubernetes.io/name: webhook app.kubernetes.io/instance: cert-manager app.kubernetes.io/managed-by: Tiller helm.sh/chart: webhook-v0.9.0 spec: secretName: cert-manager-webhook-webhook-tls duration: 8760h # 1y issuerRef: name: cert-manager-webhook-ca dnsNames: - cert-manager-webhook - cert-manager-webhook.cert-manager - cert-manager-webhook.cert-manager.svc