Configuring cluster issuer for Certificate Manager
Certificate Manager is installed by default as part of the Cloudera Embedded Container Service installation.
To enable the usage of cert-manager in Cloudera AI, cluster issuers must be configured with the appropriate annotations.
Cloudera AI will prioritize using the
shortlived
issuer, if available, to sign certificates for
temporary workloads such as jobs, sessions, and experiments. For Cloudera AI infrastructure endpoints and application
workloads, the longlived
issuer will be used. In cases where a
shortlived
issuer is not configured, the
longlived
issuer will handle certificate signing for all
workloads and infrastructure endpoints.