
cert-manager webhook for Hurricane Electric hosted DNS

Primary LanguageGoApache License 2.0Apache-2.0

ACME webhook for Hurricane Electric Hosted DNS

This solver can be used when you want to use cert-manager with Hurricane Electric hosted DNS zones.

Note This is almost direct copy of vadikim's cert-manager-webhook-hetzner with heavy adjustments to accomodate using Hurricane Electric's Dynamic DNS interface.

This is not considered ready for production, nor has it been tested. I do not know enough Go to make heads or tails about the code but I know enough to be dangerous.

This version is provided as-is, without any guarantees that it won't wreck your coffee maker or kubernetes installation. Use at your own risk!




Follow the instructions using the cert-manager documentation to install it within your cluster.


Using public helm chart

helm repo add cert-manager-webhook-henet https://diftraku.github.io/cert-manager-webhook-henet
# Replace the groupName value with your desired domain
helm install --namespace cert-manager cert-manager-webhook-henet cert-manager-webhook-henet/cert-manager-webhook-henet --set groupName=acme.yourdomain.tld

From local checkout

helm install --namespace cert-manager cert-manager-webhook-henet deploy/cert-manager-webhook-henet

Note: The kubernetes resources used to install the Webhook should be deployed within the same namespace as the cert-manager.

To uninstall the webhook run

helm uninstall --namespace cert-manager cert-manager-webhook-henet


Create a ClusterIssuer or Issuer resource as following:

apiVersion: cert-manager.io/v1
kind: ClusterIssuer
  name: letsencrypt-staging
    # The ACME server URL
    server: https://acme-staging-v02.api.letsencrypt.org/directory

    # Email address used for ACME registration
    email: mail@example.com # REPLACE THIS WITH YOUR EMAIL!!!

    # Name of a secret used to store the ACME account private key
      name: letsencrypt-staging

      - dns01:
            # This group needs to be configured when installing the helm package, otherwise the webhook won't have permission to create an ACME challenge for this API group.
            groupName: acme.yourdomain.tld
            solverName: hurricane-electric
              secretName: henet-secret
              apiUrl: https://dyn.dns.he.net


In order to access the henet API, the webhook needs an API token.

If you choose another name for the secret than henet-secret, ensure you modify the value of secretName in the [Cluster]Issuer.

The secret for the example above will look like this:

apiVersion: v1
kind: Secret
  name: henet-secret
  namespace: cert-manager
type: Opaque
  password: your-key-base64-encoded

Create a certificate

Finally you can create certificates, for example:

apiVersion: cert-manager.io/v1
kind: Certificate
  name: example-cert
  namespace: cert-manager
  commonName: example.com
    - example.com
    name: letsencrypt-staging
    kind: ClusterIssuer
  secretName: example-cert


Running the test suite

All DNS providers must run the DNS01 provider conformance testing suite, else they will have undetermined behaviour when used with cert-manager.

It is essential that you configure and run the test suite when creating a DNS01 webhook.

First, you need to have a Hurricane Electric account with access to the DNS control panel. You need to create a new TXT record with the name of cert-manager-dns01-tests, use TTL of 5 minutes and ensure Enable entry for dynamic dns is checked. Use the circular arrows icon to set or generate the key for dynamic updates. You can either set the zoneName parameter in testdata/henet/config.json to your zone name or use the TEST_ZONE_NAME as in the example below. You also must encode your key into base64 and put the hash into testdata/henet/henet-secret.yml file.

You can run the test suite with:

$ TEST_ZONE_NAME=example.com. make test