Manually managing TLS certificates in applications running on Kubernetes is a process that is both time-consuming and error-prone. This is where cert-manager comes into play, making the platform much more secure and sustainable by automating the certificate generation, renewal and verification processes.
The following guide explains the installation of cert-manager from start to finish in a clear and practical way.
Prerequisites
It is recommended that the following requirements are met in the environment before you start:
- Kubernetes v1.24+ (recommended)
kubectlinstalledcluster-adminauthority on the cluster- Internet access (required for Jetstack and Let’s Encrypt)
- (Optional) NGINX Ingress Controller or Gateway API
Creating Namespace
kubectl create namespace cert-manager
This step can be skipped if the namespace already exists.
Installation Methods
1) Installation with Helm
Helm is the most recommended method as it makes CRD management and component updates more streamlined.
Official documentation: 👉 https://cert-manager.io/docs/installation/helm/
2) Manual Installation with Kubectl Apply
For those who do not want to use Helm, it is possible to implement cert-manager components directly with YAML files.
Example installation steps:
Namespace
kubectl apply -f 00-namespace.yaml
CRDs
kubectl apply -f 01-crd.yaml
Secret (for providers like Cloudflare)
kubectl apply -f 01-secret.yaml
Confidential information in this file is masked. You need to enter values appropriate to your environment.
cert-manager Components
kubectl apply -f 02-certmanager.yaml
Verify Installation
kubectl get pods -n cert-manager
Must-see pods:
cert-managercert-manager-cainjectorcert-manager-webhook
Optional verification:
cmctl check api
ACME Configuration with Let’s Encrypt
Cloudflare (DNS-01 Challenge)
If you use Cloudflare, it is recommended that you create an API Token with minimum authority.
Secret Definition
apiVersion: v1
kind: Secret
metadata:
name: cloudflare-api-token-secret
namespace: cert-manager
type: Opaque
stringData:
api-token: REDACTED
ClusterIssuer (Production)
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt-prod
spec:
acme:
email: admin@tarsolution.com
server: https://acme-v02.api.letsencrypt.org/directory
privateKeySecretRef:
name: letsencrypt-prod-account-key
solvers:
- dns01:
cloudflare:
apiTokenSecretRef:
name: cloudflare-api-token-secret
key: api-token
Wildcard Certificate Sample
apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
name: wildcard-tarsolution-com
namespace: default
spec:
secretName: wildcard-tarsolution-com-tls
issuerRef:
name: letsencrypt-prod
kind: ClusterIssuer
dnsNames:
- tarsolution.com
- "*.tarsolution.com"
HTTP-01 (NGINX Ingress)
HTTP-01 challenge can be used in environments that do not support DNS.
apiVersion: cert-manager.io/v1
kind: Issuer
metadata:
name: letsencrypt-http01
namespace: default
spec:
acme:
email: admin@tarsolution.com
server: https://acme-staging-v02.api.letsencrypt.org/directory
privateKeySecretRef:
name: letsencrypt-http01-account-key
solvers:
- http01:
ingress:
ingressClassName: nginx
Best Practices
- Test in staging environment first
- Generate minimum authorized token for Cloudflare
- You can make the scope namespace specific by using
Issuerinstead ofClusterIssuer - Track certification expirations with Prometheus + Alertmanager
Troubleshooting
Common problems and checks:
- DNS-01: Token authority, zone selection, DNS propagation
- HTTP-01:
.well-knownpath, ingressClassName, port redirects - Error analysis with
kubectl describe certificate <name>
Uninstall Process
If you did a manual installation:
kubectl delete -f 02-certmanager.yaml
kubectl delete -f 01-secret.yaml
kubectl delete -f 01-crd.yaml
kubectl delete -f 00-namespace.yaml
If you installed via Helm:
helm uninstall cert-manager -n cert-manager
By following the installation step by step, you can ensure reliable and automatic TLS management in your Kubernetes environment.
Source: