<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>ACME on 黄文卓 | DevOps Engineer</title><link>https://socake.github.io/tags/acme/</link><description>Recent content in ACME on 黄文卓 | DevOps Engineer</description><generator>Hugo -- gohugo.io</generator><language>zh-CN</language><managingEditor>17691281867@163.com (Wenzhuo Huang)</managingEditor><webMaster>17691281867@163.com (Wenzhuo Huang)</webMaster><copyright>© 2026 Wenzhuo Huang</copyright><lastBuildDate>Sat, 15 Feb 2025 14:30:00 +0800</lastBuildDate><atom:link href="https://socake.github.io/tags/acme/index.xml" rel="self" type="application/rss+xml"/><item><title>cert-manager 生产级实战：从 Let's Encrypt 到企业内网 PKI 的完整路线</title><link>https://socake.github.io/posts/cert-manager-production/</link><pubDate>Sat, 15 Feb 2025 14:30:00 +0800</pubDate><author>17691281867@163.com (Wenzhuo Huang)</author><guid>https://socake.github.io/posts/cert-manager-production/</guid><description>cert-manager 几乎是每个 Kubernetes 集群的标配，但真正跑到生产的团队都会遇到：Let&amp;rsquo;s Encrypt 限流被打爆、通配符证书续期失败、内部服务想要私有 CA、Istio / Gateway API 的证书怎么发。这篇把一年里我在 5 个集群上做 cert-manager 运维踩过的坑写成一份实操手册。</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://socake.github.io/posts/cert-manager-production/featured.jpg"/></item></channel></rss>