aethercert
Linux and containers

Automated TLS secrets for Kubernetes

The Kubernetes package writes each renewed certificate and key into a TLS secret in the namespace you choose. Ingress controllers and workloads that reference the secret use the new certificate.

The deployment steps defined in this package's manifest.

At a glance

Package
kubernetes-target 2.0.0
Compatibility
Kubernetes API Server >=1.22 <2.0
Runs from
Any Windows or Linux agent with network access to it
Mechanism
REST API
Authentication
Bearer token
Capabilities
Import certificate and key
Deployment steps
upsertSecret
Rollback
None
Key usage
No requirement

What it does

An agent with access to the cluster API server creates the TLS secret on first issue and updates it on renewal, authenticating with a service account token that needs only get and patch on secrets in that namespace.

This brings certificates from authorities that have no in-cluster integration - AD CS through the CA connector, a REST CA - into the cluster, alongside the rest of your fleet.

How it runs

  1. 01

    upsertSecret

    The kubernetes.io/tls secret is created or updated with certificate and key.

What you configure

  • API server host and port
  • Namespace (default: default)
  • Secret name
  • Service account token (stored encrypted)

Prerequisites

  • An agent with network access to the Kubernetes API server
  • A service account with get and patch on secrets in the namespace

Limitations

  • One secret per deploy target.
  • Workloads that read the certificate only at start-up need their own restart mechanism.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Frequently asked questions

Kubernetes

Is this a replacement for cert-manager?

It solves a different case: one control plane for certificates across servers, appliances and clusters, including authorities cert-manager does not reach, such as AD CS through the CA connector.

What permissions does the token need?

Get and patch on secrets in the configured namespace.

Automate Kubernetes

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.