{{- /* Cluster-scoped ca Issuer using the Root CA Secret synced from Vault. Resolvable from any namespace via `issuerRef.kind: ClusterIssuer`, so app namespaces can request leaf certs without copying the Root CA around. */}} apiVersion: cert-manager.io/v1 kind: ClusterIssuer metadata: name: {{ .Values.issuerName }} {{- with .Values.commonAnnotations }} annotations: {{- toYaml . | nindent 4 }} {{- end }} {{- with .Values.commonLabels }} labels: {{- toYaml . | nindent 4 }} {{- end }} spec: ca: secretName: {{ .Values.rootCASecretName }}