Configuring cluster issuer for cert-manager
Cert-manager is installed by default as part of the Cloudera Embedded Container Service installation.
To enable the usage of cert-manager in Cloudera AI, cluster issuers must be configured with the appropriate annotations.
Cloudera AI prioritizes using the
shortlived issuer, if available, to sign certificates for
temporary workloads such as jobs, sessions, and experiments. For Cloudera AI infrastructure endpoints and application
workloads, the longlived issuer is used. In cases where a
shortlived issuer is not configured, the
longlived issuer handles certificate signing for all workloads
and infrastructure endpoints.
