Skip to main content
← All posts·
Platform Engineering

cert-manager for Regulated Enterprises: Automated TLS Certificate Management

cert-manager guide for regulated enterprises. Automated TLS certificate lifecycle in Kubernetes — issuance, renewal, and rotation with Let's Encrypt, private CA, and Vault PKI. Covers 47-day certificate compliance, mTLS, and NIS2 encryption requirements.

Luca Berton10 min read

Certificate Management at Scale

With the industry moving to 47-day TLS certificate lifetimes, manual certificate management is no longer viable. At enterprise scale (hundreds of services, multiple clusters, internal and external certificates), automated certificate lifecycle management is a hard requirement — not a nice-to-have.

cert-manager is the standard Kubernetes solution for automated certificate management, used by the majority of production Kubernetes deployments.

cert-manager Capabilities

Automated Certificate Lifecycle

  • Automatic issuance: Create a Certificate resource, cert-manager handles the rest — CSR, validation, issuance, storage
  • Automatic renewal: Certificates renewed before expiry (default: renew when 2/3 of lifetime has passed)
  • Multiple issuers: Let's Encrypt (public), Vault PKI (internal), AWS ACM PCA, Venafi, step-ca — use different CAs for different purposes
  • Ingress integration: Annotate an Ingress resource, cert-manager automatically provisions and manages the TLS certificate
  • Gateway API support: First-class integration with Kubernetes Gateway API

Compliance Features

  • 47-day certificates: cert-manager handles frequent rotation automatically — no operational burden increase
  • Private CA: Issue certificates from your internal CA for mTLS between services — no public CA dependency for internal traffic
  • Certificate policies: Enforce minimum key sizes, required SANs, allowed issuers per namespace
  • Audit events: Kubernetes events for every certificate operation — issuance, renewal, failure
  • Metrics: Prometheus metrics for certificate expiry, renewal success/failure, issuance latency

Common Patterns for Regulated Environments

  • External traffic: Let's Encrypt via cert-manager for public-facing services (Ingress/Gateway)
  • Internal mTLS: Vault PKI or internal CA issuer for service-to-service encryption
  • Istio integration: cert-manager as Istio's certificate provider (istio-csr) — unified certificate management
  • Cross-cluster: cert-manager + trust-manager for distributing CA bundles across clusters
  • Monitoring: Grafana dashboard showing certificate expiry timeline, renewal rates, and failures
📘 Book

Kubernetes Recipes

Practical guide for container orchestration and deployment — hands-on patterns you can use today.

View on Amazon →

Operational Considerations

  1. Monitor renewal failures — A failed renewal means a certificate will expire. Alert aggressively on cert-manager errors.
  2. Rate limiting awareness — Let's Encrypt has rate limits. Use staging issuer for testing, production for live certificates.
  3. DNS challenge for wildcards — Wildcard certificates require DNS-01 challenges. Ensure DNS provider integration is configured.
  4. Backup CA certificates — If using a self-signed root CA, back up the CA key securely (Vault or HSM).
  5. Test in staging — Always test certificate changes in staging first. A misconfigured issuer can take down TLS for all services.
cert-manager
TLS
certificates
Kubernetes
encryption
Let's Encrypt
regulated enterprises

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →