@@ -176,12 +176,12 @@ func (r *Reconciler) reconcileClusterCertificate(
176176 r.Client.Get(ctx, client.ObjectKeyFromObject(existing), existing)))
177177
178178 leaf := &pki.LeafCertificate{}
179- primaryServiceDNSNames, err := naming.ServiceDNSNames(ctx, primaryService)
179+ primaryServiceDNSNames, err := naming.ServiceDNSNames(ctx, primaryService, cluster.Spec.ClusterServiceDNSSuffix )
180180 if err != nil {
181181 return nil, errors.Wrap(err, "get primary service dns names")
182182 }
183183
184- replicaServiceDNSNames, err := naming.ServiceDNSNames(ctx, replicaService)
184+ replicaServiceDNSNames, err := naming.ServiceDNSNames(ctx, replicaService, cluster.Spec.ClusterServiceDNSSuffix )
185185 if err != nil {
186186 return nil, errors.Wrap(err, "get replica service dns names")
187187 }
@@ -256,7 +256,7 @@ func (r *Reconciler) reconcileClusterCertificate(
256256// using the current root certificate
257257func (*Reconciler) instanceCertificate(
258258 ctx context.Context, instance *appsv1.StatefulSet,
259- existing, intent *corev1.Secret, root *pki.RootCertificateAuthority,
259+ existing, intent *corev1.Secret, root *pki.RootCertificateAuthority, dnsSuffix string,
260260) (
261261 *pki.LeafCertificate, error,
262262) {
@@ -267,7 +267,7 @@ func (*Reconciler) instanceCertificate(
267267
268268 // RFC 2818 states that the certificate DNS names must be used to verify
269269 // HTTPS identity.
270- dnsNames := naming.InstancePodDNSNames(ctx, instance)
270+ dnsNames := naming.InstancePodDNSNames(ctx, instance, dnsSuffix )
271271 dnsFQDN := dnsNames[0]
272272
273273 if err == nil {
0 commit comments