x509.systems

cert-manager vs Let's Encrypt

How cert-manager and Let's Encrypt differ on deployment, pricing, openness and what each is actually built for.

cert-managerLet's Encrypt
TypeKubernetes controllerPublic CA (free)
DeploymentSelf-hosted (K8s)SaaS (ACME)
How it worksA Kubernetes controller that turns Certificate resources into real certificates from any configured issuer — ACME, Vault, private CAs — and renews them automatically as secrets. A CNCF graduated project.Issues domain-validated TLS certificates at no cost, exclusively through the ACME protocol. Short 90-day lifetimes force automation, which is the point: renewal is a cron job, not a calendar reminder.
Pricing*FreeFree
Free tierYesYes
Open sourceApache-2.0Boulder (MPL-2.0)
Compliance—WebTrust, CA/B Forum
Best forCertificates inside a Kubernetes clusterPublic web TLS on anything you can automate

cert-manager

  • The de facto standard in Kubernetes
  • Issuer-agnostic — ACME, Vault, private CAs
  • Free and heavily battle-tested
  • Kubernetes only — nothing outside the cluster
  • No estate-wide visibility or reporting

Let's Encrypt

  • Free and genuinely unlimited in practice
  • ACME everywhere — client support is universal
  • Short lifetimes push good automation hygiene
  • Domain validation only — no OV or EV
  • No support contract to escalate to

Bottom line

Choose cert-manager for certificates inside a kubernetes cluster. Choose Let's Encrypt for public web tls on anything you can automate.

* Indicative list pricing (vendor documentation and public pricing pages, August 2026).