x509.systems

Ccert-manager

The default way certificates get issued inside Kubernetes — free, ubiquitous, and only for Kubernetes.

Kubernetes controllerSelf-hosted (K8s)By CNCF / VenafiSince 2017Open source: Apache-2.0
Type
Kubernetes controller
How it works
A Kubernetes controller that turns Certificate resources into real certificates from any configured issuer — ACME, Vault, private CAs — and renews them automatically as secrets. A CNCF graduated project.
Deployment
Self-hosted (K8s)
Pricing*
Free
Free tier
Yes
Open source
Apache-2.0
Compliance
—
Best for
Certificates inside a Kubernetes cluster
Notable
CNCF graduated project

* Indicative list pricing at August 2026 (vendor documentation and public pricing pages, August 2026), not a quote.

Strengths

  • The de facto standard in Kubernetes
  • Issuer-agnostic — ACME, Vault, private CAs
  • Free and heavily battle-tested
  • Declarative, fits GitOps naturally

Trade-offs

  • Kubernetes only — nothing outside the cluster
  • No estate-wide visibility or reporting
  • Misconfiguration silently stops renewals
  • Commercial support needs a third party

Visit cert-manager → Documentation

Listed for comparison as of August 2026 — not an endorsement, and cert-manager did not pay for placement. See disclosure.

Compare cert-manager with…

cert-manager vs DigiCertcert-manager vs Sectigocert-manager vs Let's Encrypt