kube-lego automated requesting Let's Encrypt certificates for services exposed through Kubernetes Ingress. It helped teams provide trusted HTTPS without manually issuing and replacing a certificate for each endpoint. The tool was deprecated in favor of cert-manager, which uses a broader certificate-management model. Existing users need to preserve their issuer accounts, hostname validation and certificate consumers while moving renewal responsibility, rather than simply remove the old controller and hope certificates continue updating.
Current guidance
kube-lego was deprecated in favor of cert-manager. Use its restored instructions as history, not a current certificate-management setup.
The change is from an older Ingress-focused certificate workflow to a broader certificate controller and custom resources. Read current cert-manager installation guidance alongside the historical migration explanation.
Inventory issuers, account credentials, challenge methods and certificate consumers. Test issuance and renewal on a controlled hostname, avoiding unnecessary production CA rate-limit pressure. Keep the previous certificate usable while verifying the new renewal path.
Historical upstream link check · 2026-10-09
The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. GitHub marks jetstack/kube-lego as archived. This confirms the repository's read-only archive state; any successor or supported distribution needs separate evidence. Link availability does not certify the historical installation instructions or current security support.
Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.
Historical Kubedex content
Preserved for context. Commands, versions, prices and results below reflect the original research.
kube-lego automatically requests certificates for Kubernetes Ingress resources from Let’s Encrypt. This chart bootstraps a kube-lego deployment on a Kubernetes cluster using the Helm package manager. kube-lego is in maintenance mode only. There is no plan to support any new features. The latest Kubernetes release that kube-lego officially supports is 1.8. The officially endorsed successor is cert-manager.
Requirements
- Kubernetes 1.2+
- Compatible ingress controller (nginx or GCE see here)
- Non-production use case
Features
Recognizes the need of a new certificate for this cases:
- No certificate existing
- The existing certificate is not containing all domain names
- The existing certificate is expired or near to its expiry date (cf. option LEGO_MINIMUM_VALIDITY)
- The existing certificate is unparseable, invalid or not matching the secret key
- Creates a user account (incl. private key) for Let’s Encrypt and stores it in Kubernetes secrets (secret name is configurable via LEGO_SECRET_NAME)
- Obtains the missing certificates from Let’s Encrypt and authorizes the request with the HTTP-01 challenge
- Makes sure that the specific Kubernetes objects (Services, Ingress) contain the rights configuration for the HTTP-01 challenge to succeed
- Official Kubernetes Helm chart for simplistic deployment.
Run kube-lego
- GCE
- nginx controller
The default value of LEGO_URL is the Let’s Encrypt staging environment. If you want to get “real” certificates you have to configure their production env.
Please note:
- The secretName statements have to be unique per namespace
- secretName is required (even if no secret exists with that name, as it will be created by kube-lego)
- Setups which utilize 1:1 NAT need to ensure internal resources can reach gateway controlled public addresses.
- Additionally, your domain must point to your externally available Load Balancer (either directly or via 1:1 NAT)
Ingress controllers
Nginx Ingress Controller
- available through image gcr.io/google_containers/nginx-ingress-controller
- fully supports kube-lego from version 0.8 onwards
GCE Loadbalancers
- you don’t have to maintain the ingress controller yourself, you pay GCE to do that for you
- every ingress resource creates one GCE load balancer
- all service that you want to expose, have to be Type=NodePort
Sources & further reading
Spotted something that needs another look?
Help improve this page →