apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: hubble-server-certs namespace: kube-system spec: issuerRef: group: cert-manager.io kind: ClusterIssuer name: ca-issuer secretName: hubble-server-certs commonName: "*.default.hubble-grpc.cilium.io" dnsNames: - "*.default.hubble-grpc.cilium.io" duration: 8760h0m0s privateKey: rotationPolicy: Always isCA: false usages: - signing - key encipherment - server auth - client auth