Automated TLS secrets for Kubernetes
The Kubernetes package writes each renewed certificate and key into a TLS secret in the namespace you choose. Ingress controllers and workloads that reference the secret use the new certificate.
package kubernetes-target 2.0.0
upsertSecret
At a glance
- Package
kubernetes-target 2.0.0- Compatibility
Kubernetes API Server >=1.22 <2.0- Runs from
- Any Windows or Linux agent with network access to it
- Mechanism
- REST API
- Authentication
- Bearer token
- Capabilities
- Import certificate and key
- Deployment steps
- upsertSecret
- Rollback
- None
- Key usage
- No requirement
What it does
An agent with access to the cluster API server creates the TLS secret on first issue and updates it on renewal, authenticating with a service account token that needs only get and patch on secrets in that namespace.
This brings certificates from authorities that have no in-cluster integration - AD CS through the CA connector, a REST CA - into the cluster, alongside the rest of your fleet.
How it runs
- 01
upsertSecret
The kubernetes.io/tls secret is created or updated with certificate and key.
What you configure
- API server host and port
- Namespace (default: default)
- Secret name
- Service account token (stored encrypted)
Prerequisites
- An agent with network access to the Kubernetes API server
- A service account with get and patch on secrets in the namespace
Limitations
- One secret per deploy target.
- Workloads that read the certificate only at start-up need their own restart mechanism.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Linux and containers
Documentation
Frequently asked questions
Kubernetes
Is this a replacement for cert-manager?
It solves a different case: one control plane for certificates across servers, appliances and clusters, including authorities cert-manager does not reach, such as AD CS through the CA connector.
What permissions does the token need?
Get and patch on secrets in the configured namespace.
Automate Kubernetes
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.