apiVersion: cert-manager.io/v1 kind: Issuer metadata: name: selfsigned-issuer spec: selfSigned: {} --- apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: server-ca spec: isCA: true commonName: my-selfsigned-server-ca secretName: server-ca-key-pair privateKey: algorithm: ECDSA size: 256 issuerRef: name: selfsigned-issuer kind: Issuer group: cert-manager.io --- apiVersion: cert-manager.io/v1 kind: Issuer metadata: name: server-ca-issuer spec: ca: secretName: server-ca-key-pair --- apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: client-ca spec: isCA: true commonName: my-selfsigned-client-ca secretName: client-ca-key-pair privateKey: algorithm: ECDSA size: 256 issuerRef: name: selfsigned-issuer kind: Issuer group: cert-manager.io --- apiVersion: cert-manager.io/v1 kind: Issuer metadata: name: client-ca-issuer spec: ca: secretName: client-ca-key-pair