Technology · Ebook
cert-manager: Automating TLS Certificates on Kubernetes
by Shriira Press
cert-manager is the standard way to automate TLS certificates on Kubernetes: declare the certificate you want and it requests, validates, stores, and renews it for you — retiring the expired-certificate outage for good. This free book teaches it from first principles: just enough TLS and PKI to be dangerous, cert-manager's operator architecture and CRDs, Issuers and ClusterIssuers, the Certificate resource and its lifecycle, the ACME protocol with HTTP-01 and DNS-01 challenges, automatic HTTPS through Ingress annotations, private CAs and Vault for internal services and mTLS, a systematic troubleshooting method, and the practices that keep certificate automation reliable and secure. Ten focused chapters with real manifests and clear diagrams that take you from concepts to hands-off HTTPS everywhere.
Contents
- 1Preface
- 2Chapter 1 — What cert-manager Is
- 3Chapter 2 — TLS and PKI Basics
- 4Chapter 3 — Architecture and Resources
- 5Chapter 4 — Issuers and ClusterIssuers
- 6Chapter 5 — The Certificate Resource
- 7Chapter 6 — ACME and Domain Validation
- 8Chapter 7 — Ingress Integration and Automatic TLS
- 9Chapter 8 — Private CAs and Other Issuers
- 10Chapter 9 — Troubleshooting
- 11Chapter 10 — Best Practices and Putting It Together
