Certificate Management at Scale
With the industry moving to 47-day TLS certificate lifetimes, manual certificate management is no longer viable. At enterprise scale (hundreds of services, multiple clusters, internal and external certificates), automated certificate lifecycle management is a hard requirement — not a nice-to-have.
cert-manager is the standard Kubernetes solution for automated certificate management, used by the majority of production Kubernetes deployments.
cert-manager Capabilities
Automated Certificate Lifecycle
- Automatic issuance: Create a Certificate resource, cert-manager handles the rest — CSR, validation, issuance, storage
- Automatic renewal: Certificates renewed before expiry (default: renew when 2/3 of lifetime has passed)
- Multiple issuers: Let's Encrypt (public), Vault PKI (internal), AWS ACM PCA, Venafi, step-ca — use different CAs for different purposes
- Ingress integration: Annotate an Ingress resource, cert-manager automatically provisions and manages the TLS certificate
- Gateway API support: First-class integration with Kubernetes Gateway API
Compliance Features
- 47-day certificates: cert-manager handles frequent rotation automatically — no operational burden increase
- Private CA: Issue certificates from your internal CA for mTLS between services — no public CA dependency for internal traffic
- Certificate policies: Enforce minimum key sizes, required SANs, allowed issuers per namespace
- Audit events: Kubernetes events for every certificate operation — issuance, renewal, failure
- Metrics: Prometheus metrics for certificate expiry, renewal success/failure, issuance latency
Common Patterns for Regulated Environments
- External traffic: Let's Encrypt via cert-manager for public-facing services (Ingress/Gateway)
- Internal mTLS: Vault PKI or internal CA issuer for service-to-service encryption
- Istio integration: cert-manager as Istio's certificate provider (istio-csr) — unified certificate management
- Cross-cluster: cert-manager + trust-manager for distributing CA bundles across clusters
- Monitoring: Grafana dashboard showing certificate expiry timeline, renewal rates, and failures
Kubernetes Recipes
Practical guide for container orchestration and deployment — hands-on patterns you can use today.
View on Amazon →Operational Considerations
- Monitor renewal failures — A failed renewal means a certificate will expire. Alert aggressively on cert-manager errors.
- Rate limiting awareness — Let's Encrypt has rate limits. Use staging issuer for testing, production for live certificates.
- DNS challenge for wildcards — Wildcard certificates require DNS-01 challenges. Ensure DNS provider integration is configured.
- Backup CA certificates — If using a self-signed root CA, back up the CA key securely (Vault or HSM).
- Test in staging — Always test certificate changes in staging first. A misconfigured issuer can take down TLS for all services.
Luca Berton