cert-manager

Kubernetes certificate controller supporting Let's Encrypt, Vault, and more

ToolSecrets ManagementOpen SourceSelf-hosted

Pricing: Free (open source); enterprise support from Venafi/CyberArk

Reviewed by the CyberSecTool editorial team against the public sources cited below · Last reviewed April 2026 · How we review listings

What is cert-manager?

cert-manager is a widely used Kubernetes controller for X.509 certificate management. It automates the issuance and renewal of certificates from Let's Encrypt, HashiCorp Vault, Venafi, AWS Private CA, Google CAS, and internal CA setups. cert-manager is a CNCF Graduated project originally built by Jetstack, and it's the go-to tool for any team running TLS on Kubernetes.

Best for: Any Kubernetes team that needs TLS. Which is nearly all of them
Pros
  • De facto standard for TLS on Kubernetes
  • Wide CA provider support (public and private)
  • Automatic renewal eliminates expired-cert incidents
  • Massive community and active development
Things to check
  • Kubernetes-only; not for non-container workloads
  • Configuration has many CRDs to understand (Issuer, ClusterIssuer, Certificate)
  • ACME rate limits can surprise teams doing heavy issuance
  • Complex certificate chains require custom Issuer logic

Reported in public reviews and vendor documentation. See sources below.

Key Features

Automatic Let's Encrypt certificate issuance
Support for HashiCorp Vault PKI, Venafi, AWS Private CA
ACME HTTP-01 and DNS-01 solvers
Automatic renewal before expiry
Certificate and Issuer CRDs
Multi-cluster support via federation
Approver policies for manual/automated signing
Ingress annotations for TLS
Istio and Gateway API integration
CNCF Graduated project

Are you cert-manager? Improve this listing with screenshots, case studies and more.

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent cert-manager? Request a correction.