Skip to content

Trust-manager bundles

Deploy these packages when workloads need centrally managed CA trust distributed across selected namespaces, such as approved DoD PKI roots or public Web PKI roots. The CMTM package provides the trust-manager controller, webhook, and Bundle API; the optional CMTMB package composes selected sources into a package-managed Bundle and target ConfigMaps. Workloads must explicitly mount or reference the generated targets.

Big Bang has two separate maintained packages for trust-manager:

The aggregate Bundle is disabled by default. Enable it only when workloads need the package-managed trust bundle.

Package ordering

Install and reconcile cert-manager-trust-manager before cert-manager-trust-manager-bundle. The bundle package creates a normal Helm-managed Bundle custom resource and depends on the controller package’s CRD and webhook.

The two packages have independent Helm lifecycles. Enabling the bundle package does not enable the controller package, and the bundle package does not inspect or mutate the separate trust-manager release.

DoD trust bundle

Enable the controller package and the bundle package explicitly. These package repositories are maintained separately from the umbrella chart, so the example includes the packageConfiguration.version: v1 discriminator and Git source fields required for custom package entries. Replace <CMTM_TAG> and <CMTMB_TAG> with compatible, currently published release tags for the environment before applying the configuration:

packageConfiguration:
  version: v1

packages:
  cert-manager-trust-manager:
    enabled: true
    namespace:
      name: cert-manager
    helmRelease:
      namespace: bigbang
    bbCommonValues: true
    dependsOn:
      - name: cert-manager
        namespace: bigbang
    sourceType: git
    git:
      repo: https://repo1.dso.mil/big-bang/product/maintained/cert-manager-trust-manager.git
      path: chart
      tag: <CMTM_TAG> # replace with a published compatible tag

  cert-manager-trust-manager-bundle:
    enabled: true
    namespace:
      name: cert-manager
    helmRelease:
      namespace: bigbang
    bbCommonValues: true
    dependsOn:
      - name: cert-manager-trust-manager
        namespace: bigbang
    sourceType: git
    git:
      repo: https://repo1.dso.mil/big-bang/product/maintained/cert-manager-trust-manager-bundle.git
      path: chart
      tag: <CMTMB_TAG> # replace with a published compatible tag
    values:
      namespace: cert-manager
      bundle:
        enabled: true
        sources:
          dod:
            enabled: true

The DoD source is the package-owned, provenance-tracked Cyber Exchange artifact. It is not a certificate-generation or private-key-management feature.

Public trust bundle

Public trust is an explicit two-package contract. Use the same complete package source configuration as above, then enable the upstream default package in cert-manager-trust-manager and the public source in cert-manager-trust-manager-bundle:

packageConfiguration:
  version: v1

packages:
  cert-manager-trust-manager:
    enabled: true
    namespace:
      name: cert-manager
    helmRelease:
      namespace: bigbang
    bbCommonValues: true
    dependsOn:
      - name: cert-manager
        namespace: bigbang
    sourceType: git
    git:
      repo: https://repo1.dso.mil/big-bang/product/maintained/cert-manager-trust-manager.git
      path: chart
      tag: <CMTM_TAG> # replace with a published compatible tag
    values:
      upstream:
        defaultPackage:
          enabled: true

  cert-manager-trust-manager-bundle:
    enabled: true
    namespace:
      name: cert-manager
    helmRelease:
      namespace: bigbang
    bbCommonValues: true
    dependsOn:
      - name: cert-manager-trust-manager
        namespace: bigbang
    sourceType: git
    git:
      repo: https://repo1.dso.mil/big-bang/product/maintained/cert-manager-trust-manager-bundle.git
      path: chart
      tag: <CMTMB_TAG> # replace with a published compatible tag
    values:
      namespace: cert-manager
      bundle:
        enabled: true
        sources:
          public:
            enabled: true

Do not enable the bundle package’s public source without also enabling the controller package’s upstream default package. Public trust remains opt-in and is not enabled by default.

Source and target behavior

The aggregate Bundle can combine the supported DoD, public, and custom sources. Initial target support is ConfigMap. Workloads must mount or reference the generated target themselves; creating a Bundle does not automatically change workload configuration.

The default target is namespace-scoped. An omitted or explicitly empty namespace selector targets the configured trust-manager namespace. Configure an explicit label or expression selector when the trust material should be distributed to another namespace set. This package does not currently provide an all-namespaces opt-in.

Secret targets and workload mount/reference configuration remain follow-up scope. For the complete source, selector, target, schema, lifecycle, collision, provenance, and maintenance contract, see the CMTMB package overview and CMTMB maintenance guide.

For controller, webhook, CRD, and upstream default-package behavior, see the CMTM package overview and CMTM maintenance guide.

Lifecycle and collisions

The aggregate Bundle is a normal Helm resource, not a Helm hook. Normal install, upgrade, rollback, disablement, rename, and uninstall behavior therefore applies.

Because a Bundle is cluster-scoped, the package fails closed when the configured name already exists without matching Helm ownership metadata. Review and adopt an existing resource explicitly before enabling the package; it will not silently take ownership.