On this page
Overview
cert-manager adds Certificate and issuer resource types to Kubernetes and runs controllers that automate certificate issuance, renewal, and use. It supports sources including Let's Encrypt through ACME, HashiCorp Vault, CyberArk Certificate Manager, and in-cluster issuers.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Manage certificates and issuers as Kubernetes resources
Certificate and Issuer or ClusterIssuer resources express desired certificate state while controllers continuously reconcile issuance and status.
Sources: [1]
Choose among ACME, Vault, and other certificate sources
The project documents Let's Encrypt and other ACME providers, HashiCorp Vault, CyberArk Certificate Manager, and local in-cluster issuance as supported sources.
Sources: [1]
Renew certificates before expiration
cert-manager monitors certificate validity and attempts renewal before expiry, reducing manual rotation work and outage risk. Official documentation also covers Ingress-oriented TLS workflows.
Sources: [1]
Best fit
Fits platforms managing Kubernetes TLS lifecycle declaratively
It is useful when platform teams want Ingress and service certificates issued and renewed through cluster resources rather than application-specific scripts.
Sources: [1]
Before adoption
Operate CRDs, controllers, and webhooks as cluster components
Official releases publish installation manifests containing the CRDs and controller stack. Treat cert-manager as cluster infrastructure with explicit upgrade, monitoring, and failure-domain planning.
Sources: [3]
Design issuer credentials and permission boundaries per issuance method
External CAs, Vault, and ACME require method-specific credentials, network access, and Kubernetes permissions. ClusterIssuer use also expands the scope beyond a single namespace and should be governed accordingly.
Official sources
- [1]cert-manager v1.21.2 README(2026-10-03)
- [2]cert-manager v1.21.2 go.mod(2026-10-03)
- [3]cert-manager v1.21.2 release(2026-10-03)
- [4]cert-manager Apache-2.0 license(2026-10-03)
Supplemental curator note
cert-manager is useful when certificate lifecycle work should move from application-specific scripts into Kubernetes resources. Keep issuer credentials and certificate Secret permissions narrowly scoped, and decide namespace boundaries and ClusterIssuer usage before rollout.
Try it in 3 steps
- 1
Apply cert-manager v1.21.2 to a cluster
Install the CRDs, controller, webhook, cainjector, and related resources from the official release manifest. Use a test cluster first because this changes cluster state.
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.21.2/cert-manager.yaml - 2
Wait for the main deployments to become ready
Confirm the controller components required for certificate processing are running.
kubectl -n cert-manager rollout status deployment/cert-manager && kubectl -n cert-manager rollout status deployment/cert-manager-webhook && kubectl -n cert-manager rollout status deployment/cert-manager-cainjector - 3
Verify the Certificate and Issuer CRDs
Confirm the APIs are registered before configuring an issuer appropriate for the environment.
kubectl get crd certificates.cert-manager.io issuers.cert-manager.io clusterissuers.cert-manager.io
Growth
Growth trends · Last 30 days
14,104 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 126
- Open PRs
- 103
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- kubernetes
- letsencrypt
- tls
- certificate
- crd
- hacktoberfest
- Stars
- 14,104
- Forks
- 2,462
- Watchers
- 144
- Open issues
- 160
- Contributors
- 382
- Owner type
- Organization
- Primary language
- Go
- License
- Apache-2.0
- Repository last updated
- Oct 3, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Rancher25,950 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Unify access and operations across multiple Kubernetes clusters
Go - Argo Workflows17,019 Stars
2 shared tag(s) · 1 shared category(s) · Same language
orchestrate container tasks on Kubernetes as DAGs or steps for batch, ML, data, and automation workflows
Go - Trivy38,205 Stars
3 shared tag(s) · 1 shared category(s) · Same language
Scan images, filesystems, repositories, VMs, and Kubernetes for CVEs, secrets, IaC issues, and licenses
Go - Cilium25,596 Stars
3 shared tag(s) · 1 shared category(s) · Same language
unify Kubernetes networking, security, and observability on an eBPF dataplane
Go - Kyverno8,212 Stars
3 shared tag(s) · 1 shared category(s) · Same language
Continuously apply policy as code through Kubernetes admission and background scans
Go - kube-bench8,209 Stars
3 shared tag(s) · 1 shared category(s) · Same language
audit Kubernetes node and cluster configuration against CIS Benchmark checks
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.