diff --git a/charts/kyverno/Chart.yaml b/charts/kyverno/Chart.yaml index 93a6aee684..05670366c5 100644 --- a/charts/kyverno/Chart.yaml +++ b/charts/kyverno/Chart.yaml @@ -36,3 +36,5 @@ annotations: description: Docs for generatecontrollerExtraResources. - kind: changed description: Enable autogen internals by default. + - kind: fixed + description: Self signed certificates not using SANs. diff --git a/charts/kyverno/templates/secret.yaml b/charts/kyverno/templates/secret.yaml index f3b891d189..c254b8963c 100644 --- a/charts/kyverno/templates/secret.yaml +++ b/charts/kyverno/templates/secret.yaml @@ -1,6 +1,7 @@ {{- if .Values.createSelfSignedCert }} {{- $ca := genCA (printf "*.%s.svc" (include "kyverno.namespace" .)) 1024 -}} -{{- $cert := genSignedCert (printf "%s.%s.svc" (include "kyverno.serviceName" .) (include "kyverno.namespace" .)) nil nil 1024 $ca -}} +{{- $svcName := (printf "%s.%s.svc" (include "kyverno.serviceName" .) (include "kyverno.namespace" .)) -}} +{{- $cert := genSignedCert $svcName nil (list $svcName) 1024 $ca -}} apiVersion: v1 kind: Secret metadata: