UNCLASSIFIED - NO CUI

Document utilizing custom CA certificates within GItlab, especially for OIDC communications

Notes from previous testing in fences:

  • each key within a k8s secret must be a single PEM encoded certificate, not a bundle.
  • all keys within a k8s secret must be unique

https://docs.gitlab.com/charts/charts/globals.html#custom-certificate-authorities