OSS Tanbou

automate TLS certificate issuance and renewal inside Kubernetes while using ACME, Vault, and other issuers through shared resources

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
14,104
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 3, 2026
On this page

Overview

cert-manager adds Certificate and issuer resource types to Kubernetes and runs controllers that automate certificate issuance, renewal, and use. It supports sources including Let's Encrypt through ACME, HashiCorp Vault, CyberArk Certificate Manager, and in-cluster issuers.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Manage certificates and issuers as Kubernetes resources

Certificate and Issuer or ClusterIssuer resources express desired certificate state while controllers continuously reconcile issuance and status.

Sources: [1]

Choose among ACME, Vault, and other certificate sources

The project documents Let's Encrypt and other ACME providers, HashiCorp Vault, CyberArk Certificate Manager, and local in-cluster issuance as supported sources.

Sources: [1]

Renew certificates before expiration

cert-manager monitors certificate validity and attempts renewal before expiry, reducing manual rotation work and outage risk. Official documentation also covers Ingress-oriented TLS workflows.

Sources: [1]

Best fit

Fits platforms managing Kubernetes TLS lifecycle declaratively

It is useful when platform teams want Ingress and service certificates issued and renewed through cluster resources rather than application-specific scripts.

Sources: [1]

Before adoption

Operate CRDs, controllers, and webhooks as cluster components

Official releases publish installation manifests containing the CRDs and controller stack. Treat cert-manager as cluster infrastructure with explicit upgrade, monitoring, and failure-domain planning.

Sources: [3]

Design issuer credentials and permission boundaries per issuance method

External CAs, Vault, and ACME require method-specific credentials, network access, and Kubernetes permissions. ClusterIssuer use also expands the scope beyond a single namespace and should be governed accordingly.

Sources: [1][3]

Do not depend on internal Go packages as a stable module API

The README states that code under pkg/ does not have a Go module compatibility guarantee. This is separate from Kubernetes API version guarantees, so direct code imports should expect breaking changes.

Sources: [1][2]

Official sources

  1. [1]cert-manager v1.21.2 README(2026-10-03)
  2. [2]cert-manager v1.21.2 go.mod(2026-10-03)
  3. [3]cert-manager v1.21.2 release(2026-10-03)
  4. [4]cert-manager Apache-2.0 license(2026-10-03)
Supplemental curator note

cert-manager is useful when certificate lifecycle work should move from application-specific scripts into Kubernetes resources. Keep issuer credentials and certificate Secret permissions narrowly scoped, and decide namespace boundaries and ClusterIssuer usage before rollout.

Try it in 3 steps

  1. 1

    Apply cert-manager v1.21.2 to a cluster

    Install the CRDs, controller, webhook, cainjector, and related resources from the official release manifest. Use a test cluster first because this changes cluster state.

    kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.21.2/cert-manager.yaml
  2. 2

    Wait for the main deployments to become ready

    Confirm the controller components required for certificate processing are running.

    kubectl -n cert-manager rollout status deployment/cert-manager && kubectl -n cert-manager rollout status deployment/cert-manager-webhook && kubectl -n cert-manager rollout status deployment/cert-manager-cainjector
  3. 3

    Verify the Certificate and Issuer CRDs

    Confirm the APIs are registered before configuring an issuer appropriate for the environment.

    kubectl get crd certificates.cert-manager.io issuers.cert-manager.io clusterissuers.cert-manager.io
Check the official README

Growth

Growth trends · Last 30 days

14,104 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
126
Open PRs
103

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • kubernetes
  • letsencrypt
  • tls
  • certificate
  • crd
  • hacktoberfest
Stars
14,104
Forks
2,462
Watchers
144
Open issues
160
Contributors
382
Owner type
Organization
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 3, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?