[EKS] [feature request]: Support specifying ACM certificate for API server
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
**Tell us about your request**
It would be great to use a valid SSL certificate for the Kubernetes API server. Kops, for example supports that since several months by allowing to specify the ARN of an existing ACM certificate: https://github.com/kubernetes/kops/pull/5414
**Which service(s) is this request for?**
EKS
**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
As a cluster administrator, I don't want to give everybody the CA to access the cluster and I want to be able to have a vanity URL for the cluster's API with a valid SSL certificate.
**Are you currently working around this issue?**
Using Kops and its ACM feature.
Contributor guide
Research direction
Start by reviewing the EKS request and the linked kops pull request for the comparable ACM certificate capability. Define the supported way to specify an existing ACM certificate ARN for the Kubernetes API server and verify that the resulting cluster can use a vanity URL with a valid certificate.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws
- Domain
- cloud, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100