jetstack/kube-lego

GCP Identity Aware Proxy interoperability.

tmc opened this issue · 1 comments

tmc commented

AFAICT the acme-challenge urls will be blocked if you enable IAP on ingress this software creates a cert for.

Is there any way to make these two play nicely together?

I don't believe this is an issue, Lego creates a backend service which it appends to the ingress resource. This means unless you enable IAP on this addition backend you should be fine.