# Automatically Apply license and SSL certificates for App Manager + Embedded Cluster (KOTS)

**URL:** <https://community.replicated.com/t/automatically-apply-license-and-ssl-certificates-for-app-manager-embedded-cluster-kots/838>\
**Category:** Uncategorized\
**Created:** [July 1, 2022, 1:48pm UTC](https://community.replicated.com/t/automatically-apply-license-and-ssl-certificates-for-app-manager-embedded-cluster-kots/838 "2022-07-01T13:48:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dex](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/dex/32/26_2.png) [@dex](https://community.replicated.com/u/dex)\
**Post date:** [July 1, 2022, 1:48pm UTC](https://community.replicated.com/t/automatically-apply-license-and-ssl-certificates-for-app-manager-embedded-cluster-kots/838/1 "2022-07-01T13:48:55Z")

</div>

Another great question

> When using the Native Scheduler, we had a way to spin up a fully installed instance with an SSL cert applied, a license uploaded, and the app installed and running. Is there a similar way to do this for KOTS?

---

<div class="post-metadata">

**Author:** ![dex](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/dex/32/26_2.png) [@dex](https://community.replicated.com/u/dex)\
**Post date:** [July 1, 2022, 2:03pm UTC](https://community.replicated.com/t/automatically-apply-license-and-ssl-certificates-for-app-manager-embedded-cluster-kots/838/2 "2022-07-01T14:03:23Z")

</div>

### License and App Config

For embedded installations, you can make use of the `kubectl kots` CLI that comes pre-baked on embedded installations. There’s an example in the [automating existing cluster install documentation](https://docs.replicated.com/enterprise/installing-existing-cluster-automation#example). For an embedded cluster, you can use the same command after the `curl https://k8s.kurl.sh/... | sudo bash` has completed. For embedded clusters, the namespace should always be `default` instead of `app-name` as in the example.

```shell
kubectl kots install $APP_NAME \
  --namespace default \
  --shared-password password \
  --license-file ./license.yaml \
  --config-values ./configvalues.yaml \
  --no-port-forward

```

### SSL Certificate

The SSL certificate can be pre-loaded after the kURL install completes by patching the secret generated. Based on [this handy thread](https://stackoverflow.com/questions/45879498/how-can-i-update-a-secret-on-kubernetes-when-it-is-generated-from-a-file), the easiest way to do this if you have the cert files `tls.crt` and `tls.key` handy is:

```shell
kubectl create secret generic kotsadm-tls \
--save-config \
--dry-run=client \
--from-file=./tls.key --from-file=./tls.crt \
-o yaml | \
kubectl apply -f -

```

Although there are a few alternatives listed there as well if you, for example, have the cert and key available as base64 encoded environment variables instead of files.

Some other related documentation on this can be found [in Uploading new TLS certs](https://kurl.sh/docs/install-with-kurl/setup-tls-certs#uploading-new-tls-certs).

---

<div class="post-metadata">

**Author:** ![jensese](https://avatars.discourse-cdn.com/v4/letter/j/54ee81/32.png) [@jensese](https://community.replicated.com/u/jensese)\
**Post date:** [October 18, 2022, 11:17pm UTC](https://community.replicated.com/t/automatically-apply-license-and-ssl-certificates-for-app-manager-embedded-cluster-kots/838/3 "2022-10-18T23:17:20Z")

</div>

This would be great for us! We instruct our customers to install with the Kubernetes Installer, `curl -sSL https://k8s.kurl.sh/APP_SLUG | sudo bash`. This is how we’re automating spinning up instances in house as well.

I tested using the kots commands (following docs and what you describe above) to automate applying a license, but that installs another admin console/app as I expected… How can I apply the license when we install our app with the “kubernetes installer” method?

> **[Installing with the Kubernetes Installer | Replicated Docs](https://docs.replicated.com/enterprise/installing-embedded-cluster)**
>
> This topic explains how to install an application on a cluster provisioned by the Replicated Kubernetes installer.

---

<div class="post-metadata">

**Author:** ![jdewinne](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/jdewinne/32/152_2.png) [@jdewinne](https://community.replicated.com/u/jdewinne)\
**Post date:** [October 19, 2022, 4:15pm UTC](https://community.replicated.com/t/automatically-apply-license-and-ssl-certificates-for-app-manager-embedded-cluster-kots/838/4 "2022-10-19T16:15:55Z")

</div>

> [@jensese](#):
>
> I tested using the kots commands (following docs and what you describe above) to automate applying a license, but that installs another admin console/app as I expected… How can I apply the license when we install our app with the “kubernetes installer” method?

Are you using the correct APP\_SLUG and license? The app\_slug will only be relevant to show the initial ico. The license will be defining the actual application that gets installed.
