cert-manager
Kubernetes add-on that issues and renews TLS certificates automatically from sources such as Let's Encrypt and HashiCorp Vault.
- GitHub stars
- 14k
- Last commit
- today
- Latest release
- v1.21.2
- Licence
- Apache-2.0
- Self-hosted
- Yes

cert-manager is an open-source Kubernetes add-on that treats certificates and certificate issuers as native cluster resources. Instead of requesting, installing and renewing TLS certificates by hand, operators declare what they need and the controller obtains and maintains it, which reduces the chance of an outage caused by an expired certificate.
It can issue certificates from several sources, including Let's Encrypt through ACME, HashiCorp Vault and CyberArk Certificate Manager, as well as from an issuer running inside the cluster itself. It also watches expiry dates and attempts renewal at a suitable time before a certificate lapses. A common use is securing Ingress resources automatically.
The project is written in Go and released under the Apache-2.0 license. It runs inside your own cluster, with several installation methods documented on cert-manager.io, plus a getting started guide and a quick start for nginx-ingress. Community help is available through the Kubernetes Slack channels and the issue tracker.
Key features
- Certificates and issuers as Kubernetes resources
- Issuance from Let's Encrypt via ACME
- HashiCorp Vault and CyberArk issuer support
- Automatic renewal before certificates expire
- Automatic TLS for Ingress resources
- Local in-cluster certificate issuance
Pricing: Free and open source under the Apache-2.0 license.


