# cert-manager

> cert-manager is a Kubernetes add-on that issues and renews TLS certificates automatically, for example from Let's Encrypt.

- Source: https://www.itwonderlab.com/cert-manager/
- Published: 2026-08-06
- Updated: 2026-08-06
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

**cert-manager** adds `Certificate`, `Issuer` and `ClusterIssuer` resources to [Kubernetes](https://www.itwonderlab.com/kubernetes/). It asks an authority such as Let's Encrypt for a certificate, stores it in a Secret and renews it before it expires. Ingress controllers such as [Traefik](https://www.itwonderlab.com/traefik/) and [NGINX](https://www.itwonderlab.com/nginx/) use that Secret for HTTPS.

### Key concepts

- **Issuer**: where certificates come from (ACME, CA, Vault).
- **Certificate**: the request and its Secret.
- **Challenge**: HTTP-01 or DNS-01 validation.

### Learn it

Install it with [Helm](https://www.itwonderlab.com/install-kubernetes-helm/) and see [AWS Certificate Manager](https://www.itwonderlab.com/aws-acm/) for the AWS service.
