[13:53:41] jhathaway: "depends" :) [13:54:16] In wikikube we still have some manual cergen certs which are used by the envoy service proxy [13:54:55] the cert-manager certificates that are consumed by the istio-ingressgateway are created in the admin_ng part (helmfile_namespace.yaml IIRC) [13:55:26] because istio-ingress requires them to be in the istio-system namespace, not the namespace of the service [13:55:44] and we don't want deployers to have write access there for obvious reasons