# Generate a CA Certificate used to sign certificates for the webhook apiVersion: certmanager.k8s.io/v1alpha1 kind: Certificate metadata: name: cert-manager-webhook-ca namespace: "cert-manager" labels: app: webhook app.kubernetes.io/name: webhook app.kubernetes.io/instance: cert-manager app.kubernetes.io/managed-by: Tiller helm.sh/chart: webhook-v0.9.0 spec: secretName: cert-manager-webhook-ca duration: 43800h # 5y issuerRef: name: cert-manager-webhook-selfsign commonName: "ca.webhook.cert-manager" isCA: true