← All vendors
Ccert-manager
The default way certificates get issued inside Kubernetes — free, ubiquitous, and only for Kubernetes.
Kubernetes controllerSelf-hosted (K8s)By CNCF / VenafiSince 2017Open source: Apache-2.0
- Type
- Kubernetes controller
- How it works
- A Kubernetes controller that turns Certificate resources into real certificates from any configured issuer — ACME, Vault, private CAs — and renews them automatically as secrets. A CNCF graduated project.
- Deployment
- Self-hosted (K8s)
- Pricing*
- Free
- Free tier
- Yes
- Open source
- Apache-2.0
- Compliance
- —
- Best for
- Certificates inside a Kubernetes cluster
- Notable
- CNCF graduated project
* Indicative list pricing at August 2026 (vendor documentation and public pricing pages, August 2026), not a quote.
Strengths
- The de facto standard in Kubernetes
- Issuer-agnostic — ACME, Vault, private CAs
- Free and heavily battle-tested
- Declarative, fits GitOps naturally
Trade-offs
- Kubernetes only — nothing outside the cluster
- No estate-wide visibility or reporting
- Misconfiguration silently stops renewals
- Commercial support needs a third party
Visit cert-manager → Documentation
Listed for comparison as of August 2026 — not an endorsement, and cert-manager did not pay for placement. See disclosure.
Compare cert-manager with…