cert-manager automates obtaining and renewing the TLS certificates that let applications offer trusted encrypted connections. You declare the certificate you need and which certificate authority should issue it; cert-manager handles the issuance workflow and attempts renewal before expiry. Teams use it to reduce manual certificate tracking across services. It still needs a working issuer configuration and proof that you control the requested names, so failed validation must be monitored.
Current guidance
cert-manager has current upstream Helm distribution, with OCI recommended in its current installation documentation.
Install one intentionally owned certificate-management control plane and review CRD ownership, supported Kubernetes versions and cloud-provider integration. The chart package and installed controller must be compatible with existing Certificate and Issuer resources.
Test issuance, renewal and a failed challenge using a controlled environment. Protect issuer credentials and avoid deleting certificate resources as a first troubleshooting step. For ingress migration, verify that challenges and referenced Secrets remain reachable under the new routing model.
Historical upstream link check · 2026-10-09
The recorded upstream address redirects to https://github.com/cert-manager/cert-manager and returned HTTP 200 on 2026-10-09. GitHub does not mark cert-manager/cert-manager archived or disabled; this does not establish active maintenance, support or compatibility. GitHub resolves the old repository identity to cert-manager/cert-manager. Link availability does not certify the historical installation instructions or current security support.
Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.
Historical Kubedex content
Preserved for context. Commands, versions, prices and results below reflect the original research.
cert-manager is a Kubernetes add-on to automate the management and issuance of TLS certificates from various issuing sources.
It will ensure certificates are valid and up to date periodically, and attempt to renew certificates at an appropriate time before expiry.
It is loosely based upon the work of kube-lego and has borrowed some wisdom from other similar projects e.g. kube-cert-manager.
Sources & further reading
Spotted something that needs another look?
Help improve this page →