Skip to content

Commit 45563b3

Browse files
Merge pull request #1836 from lunarwhite/np-patch
Add network requirements for 'metrics server' to 'webhook, cainjector' for 1.16+ versions
2 parents 4bf2cc4 + 9bdc5ae commit 45563b3

File tree

4 files changed

+12
-12
lines changed

4 files changed

+12
-12
lines changed

content/docs/installation/best-practice.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -111,9 +111,9 @@ Here is an overview of the network requirements:
111111

112112
> ℹ️ The acmesolver Pod **does not** require access to the Kubernetes API server.
113113
114-
1. **TCP: Metrics Server -> cert-manager (controller)**:
115-
The cert-manager controller has a metrics server which listens for HTTP connections on TCP port 9402.
116-
Create a network policy which allows access to this service from your chosen metrics collector.
114+
1. **TCP: Metrics Collector -> cert-manager (controller, webhook, cainjector)**:
115+
The cert-manager controller, webhook, and cainjector have metrics servers which listen for HTTP connections on TCP port 9402.
116+
Create a network policy which allows access to these services from your chosen metrics collector.
117117

118118
## Isolate cert-manager on dedicated node pools
119119

content/v1.16-docs/installation/best-practice.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -111,9 +111,9 @@ Here is an overview of the network requirements:
111111

112112
> ℹ️ The acmesolver Pod **does not** require access to the Kubernetes API server.
113113
114-
1. **TCP: Metrics Server -> cert-manager (controller)**:
115-
The cert-manager controller has a metrics server which listens for HTTP connections on TCP port 9402.
116-
Create a network policy which allows access to this service from your chosen metrics collector.
114+
1. **TCP: Metrics Collector -> cert-manager (controller, webhook, cainjector)**:
115+
The cert-manager controller, webhook, and cainjector have metrics servers which listen for HTTP connections on TCP port 9402.
116+
Create a network policy which allows access to these services from your chosen metrics collector.
117117

118118
## Isolate cert-manager on dedicated node pools
119119

content/v1.17-docs/installation/best-practice.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -111,9 +111,9 @@ Here is an overview of the network requirements:
111111

112112
> ℹ️ The acmesolver Pod **does not** require access to the Kubernetes API server.
113113
114-
1. **TCP: Metrics Server -> cert-manager (controller)**:
115-
The cert-manager controller has a metrics server which listens for HTTP connections on TCP port 9402.
116-
Create a network policy which allows access to this service from your chosen metrics collector.
114+
1. **TCP: Metrics Collector -> cert-manager (controller, webhook, cainjector)**:
115+
The cert-manager controller, webhook, and cainjector have metrics servers which listen for HTTP connections on TCP port 9402.
116+
Create a network policy which allows access to these services from your chosen metrics collector.
117117

118118
## Isolate cert-manager on dedicated node pools
119119

content/v1.18-docs/installation/best-practice.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -111,9 +111,9 @@ Here is an overview of the network requirements:
111111

112112
> ℹ️ The acmesolver Pod **does not** require access to the Kubernetes API server.
113113
114-
1. **TCP: Metrics Server -> cert-manager (controller)**:
115-
The cert-manager controller has a metrics server which listens for HTTP connections on TCP port 9402.
116-
Create a network policy which allows access to this service from your chosen metrics collector.
114+
1. **TCP: Metrics Collector -> cert-manager (controller, webhook, cainjector)**:
115+
The cert-manager controller, webhook, and cainjector have metrics servers which listen for HTTP connections on TCP port 9402.
116+
Create a network policy which allows access to these services from your chosen metrics collector.
117117

118118
## Isolate cert-manager on dedicated node pools
119119

0 commit comments

Comments
 (0)