All OCP namespaces that want to use the letsencrypt-production-http01 cluster-issuer in their Ingress with a DNS CNAME record must include the label nerc.mghpcc.org/allow-unencrypted-routes: 'true' otherwise they will not be able to use it.
Since we have some live DNS-based Ingress running in production, we need to carefully verify and apply the nerc.mghpcc.org/allow-unencrypted-routes: 'true' label only where necessary, ensuring no duplicates while maintaining uninterrupted service.
Related to this issue