What is Cert-Manager cert-manager automates the management of X.509 certificates inside Kubernetes via CRDs — it requests, issues, renews and rotates certificates automatically.
Key concepts Issuer — a namespaced certificate signer. ClusterIssuer — a cluster-wide signer. Certificate — asks cert-manager to obtain a cert for a name. Supported backends: ACME (Let’s Encrypt), self-signed, CA, Vault, Venafi, …
Install (helm) 1helm repo add jetstack https://charts.jetstack.io 2helm repo update 3helm upgrade --install cert-manager jetstack/cert-manager \ 4 --namespace cert-manager --create-namespace \ 5 --set installCRDs=true Example: self-signed issuer 1apiVersion: cert-manager.io/v1 2kind: ClusterIssuer 3metadata: 4 name: selfsigned 5spec: 6 selfSigned: {} 1apiVersion: cert-manager.io/v1 2kind: Certificate 3metadata: 4 name: example-tls 5spec: 6 secretName: example-tls 7 dnsNames: 8 - example.com 9 issuerRef: 10 name: selfsigned 11 kind: ClusterIssuer Useful commands 1kubectl get certificate -A 2kubectl get certificaterequest -A 3kubectl describe certificate <name> -n <ns> 4 5# manual renewal (normally automatic) 6cmctl renew <name> -n <ns> Ops notes Cert-Manager stores the TLS key/cert in a <name> secret, ready for Ingress. kubectl get challenges is the first place to look for ACME/Let’s Encrypt failures.