Configuring cluster issuer for Certificate Manager
Certificate Manager is installed by default as part of the Cloudera Embedded Container Service installation.
To enable the usage of cert-manager in Cloudera AI, cluster issuers must be configured with the appropriate annotations.
Cloudera AI will prioritize using the
shortlived issuer, if available, to sign certificates for
temporary workloads such as jobs, sessions, and experiments. For Cloudera AI infrastructure endpoints and application
workloads, the longlived issuer will be used. In cases where a
shortlived issuer is not configured, the
longlived issuer will handle certificate signing for all
workloads and infrastructure endpoints.
