Managing TLS certificates manually is tedious and error-prone. Cert-manager automates the entire lifecycle: request, validate, issue, and renew — all within Kubernetes.
Installation
helm install cert-manager jetstack/cert-manager \
--namespace cert-manager --create-namespace \
--set crds.enabled=trueConfigure a Let's Encrypt Issuer
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt-production
spec:
acme:
server: https://acme-v02.api.letsencrypt.org/directory
email: admin@example.com
privateKeySecretRef:
name: letsencrypt-production-key
solvers:
- http01:
ingress:
class: nginxFor staging (higher rate limits, untrusted certs — good for testing):
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt-staging
spec:
acme:
server: https://acme-staging-v02.api.letsencrypt.org/directory
email: admin@example.com
privateKeySecretRef:
name: letsencrypt-staging-key
solvers:
- http01:
ingress:
class: nginxMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Automatic TLS on Ingress
Add one annotation and cert-manager handles everything:
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: my-app
annotations:
cert-manager.io/cluster-issuer: letsencrypt-production
spec:
tls:
- hosts:
- app.example.com
secretName: app-example-com-tls
rules:
- host: app.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: my-app
port:
number: 8080Cert-manager:
1. Sees the annotation
2. Creates a Certificate resource
3. Solves the ACME HTTP-01 challenge
4. Stores the certificate in the app-example-com-tls Secret
5. Renews automatically before expiry (default: 30 days before)
DNS-01 Challenge
For wildcard certificates or when HTTP-01 is not possible:
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt-dns
spec:
acme:
server: https://acme-v02.api.letsencrypt.org/directory
email: admin@example.com
privateKeySecretRef:
name: letsencrypt-dns-key
solvers:
- dns01:
cloudflare:
email: admin@example.com
apiTokenSecretRef:
name: cloudflare-api-token
key: api-token# Wildcard certificate
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: wildcard-example-com
spec:
secretName: wildcard-example-com-tls
issuerRef:
name: letsencrypt-dns
kind: ClusterIssuer
dnsNames:
- "*.example.com"
- "example.com"Certificate Resources
For certificates not tied to an Ingress:
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: api-internal
namespace: production
spec:
secretName: api-internal-tls
duration: 2160h # 90 days
renewBefore: 360h # Renew 15 days before expiry
issuerRef:
name: letsencrypt-production
kind: ClusterIssuer
dnsNames:
- api.internal.example.com
- api-v2.internal.example.comGet weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Monitoring Certificates
# List all certificates
kubectl get certificates -A
# Check certificate status
kubectl describe certificate app-example-com -n production
# Check certificate expiry
kubectl get certificates -A -o custom-columns=\
NAME:.metadata.name,\
READY:.status.conditions[0].status,\
EXPIRY:.status.notAfterAlert on certificate issues:
# Prometheus rule
- alert: CertManagerCertExpiringSoon
expr: certmanager_certificate_expiration_timestamp_seconds - time() < 604800
for: 1h
labels:
severity: warning
annotations:
summary: "Certificate {{ $labels.name }} expires in less than 7 days"Troubleshooting
# Check certificate request status
kubectl get certificaterequests -A
# Check ACME orders
kubectl get orders -A
# Check ACME challenges
kubectl get challenges -A
# Common issues:
# - HTTP-01: Ingress not routing /.well-known/acme-challenge/
# - DNS-01: API token permissions insufficient
# - Rate limits: Too many certificates for the same domainPrivate CA
For internal services, use a self-signed CA:
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: internal-ca
spec:
ca:
secretName: internal-ca-keyInternal mTLS certificates without external dependencies.
---
Ready to go deeper? Master Kubernetes security with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Talos Linux for Kubernetes
Talos Linux is a minimal, immutable OS designed exclusively for running Kubernetes. Learn why it exists, how it works, and when to use it instead of Ubuntu.
Falco Runtime Security Kubernetes
Falco detects runtime threats in Kubernetes using eBPF. Learn how to set up Falco for container security monitoring, write custom rules, and integrate.
OPA Gatekeeper Kubernetes Policies
OPA Gatekeeper enforces custom policies in Kubernetes at admission time. Learn how to write ConstraintTemplates, enforce security standards, and prevent.
Chainguard Enforce Supply Chain
Chainguard Enforce validates container supply chain integrity in Kubernetes using SLSA provenance, SBOMs, and image signatures. Learn how to enforce supply.
Checkov Infrastructure as Code Scan
Checkov scans Terraform, CloudFormation, Kubernetes, and Dockerfile for security misconfigurations with 1000+ built-in policies. Learn how to integrate.
CI/CD for ML on Kubernetes
Build a CI/CD pipeline for ML models using GitHub Actions, MLflow, Docker, and Kubernetes. Automate the path from training to production.
Explore topics
Browse more articles on the topics covered here.