Browse Docs

📜 CertManager

What is Cert-Manager

cert-manager automates the management of X.509 certificates inside Kubernetes via CRDs — it requests, issues, renews and rotates certificates automatically.

Key concepts

  • Issuer — a namespaced certificate signer.
  • ClusterIssuer — a cluster-wide signer.
  • Certificate — asks cert-manager to obtain a cert for a name.

Supported backends: ACME (Let’s Encrypt), self-signed, CA, Vault, Venafi, …

Install (helm)

1helm repo add jetstack https://charts.jetstack.io
2helm repo update
3helm upgrade --install cert-manager jetstack/cert-manager \
4  --namespace cert-manager --create-namespace \
5  --set installCRDs=true

Example: self-signed issuer

1apiVersion: cert-manager.io/v1
2kind: ClusterIssuer
3metadata:
4  name: selfsigned
5spec:
6  selfSigned: {}
 1apiVersion: cert-manager.io/v1
 2kind: Certificate
 3metadata:
 4  name: example-tls
 5spec:
 6  secretName: example-tls
 7  dnsNames:
 8    - example.com
 9  issuerRef:
10    name: selfsigned
11    kind: ClusterIssuer

Useful commands

1kubectl get certificate -A
2kubectl get certificaterequest -A
3kubectl describe certificate <name> -n <ns>
4
5# manual renewal (normally automatic)
6cmctl renew <name> -n <ns>

Ops notes

  • Cert-Manager stores the TLS key/cert in a <name> secret, ready for Ingress.
  • kubectl get challenges is the first place to look for ACME/Let’s Encrypt failures.
Sunday, October 4, 2026 Tuesday, August 1, 2023