cert-manager
Kubernetes certificate controller supporting Let's Encrypt, Vault, and more
ToolSecrets ManagementSelf-hosted, Open source
Pricing: Free (open source); enterprise support from Venafi/CyberArk
Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed April 2026 · How we review listings
What is cert-manager?
cert-manager is a widely used Kubernetes controller for X.509 certificate management. It automates the issuance and renewal of certificates from Let's Encrypt, HashiCorp Vault, Venafi, AWS Private CA, Google CAS, and internal CA setups. cert-manager is a CNCF Graduated project originally built by Jetstack, and it's the go-to tool for any team running TLS on Kubernetes.
Best for: Any Kubernetes team that needs TLS. Which is nearly all of them
Pros
- De facto standard for TLS on Kubernetes
- Wide CA provider support (public and private)
- Automatic renewal eliminates expired-cert incidents
- Massive community and active development
Things to check
- Kubernetes-only; not for non-container workloads
- Configuration has many CRDs to understand (Issuer, ClusterIssuer, Certificate)
- ACME rate limits can surprise teams doing heavy issuance
- Complex certificate chains require custom Issuer logic
Reported in public reviews and vendor documentation. See sources below.
Key Features
Do you work at cert-manager? to confirm the details or send us a correction.
Add the Cyber Vendor Guide badge to your site
Sources & references
Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.
Spot an error, or do you represent cert-manager? Request a correction.
Key facts
- Pricing
- Free (open source); enterprise support from Venafi/CyberArk
- Model
- Open Source
- Founded
- 2017
- Cloud
- No
- Self-hosted
- Yes
- Open source
- Yes
cert-manager Alternatives
- HashiCorp VaultIndustry-standard open-source secrets management platform...
- SPIFFE / SPIREWorkload identity standard: short-lived SVIDs replace shared...
- External Secrets OperatorK8s operator that syncs secrets from external stores into Ku...