How cert-manager and Let's Encrypt differ on deployment, pricing, openness and what each is actually built for.
| cert-manager | Let's Encrypt | |
|---|---|---|
| Type | Kubernetes controller | Public CA (free) |
| Deployment | Self-hosted (K8s) | SaaS (ACME) |
| How it works | A Kubernetes controller that turns Certificate resources into real certificates from any configured issuer — ACME, Vault, private CAs — and renews them automatically as secrets. A CNCF graduated project. | Issues domain-validated TLS certificates at no cost, exclusively through the ACME protocol. Short 90-day lifetimes force automation, which is the point: renewal is a cron job, not a calendar reminder. |
| Pricing* | Free | Free |
| Free tier | Yes | Yes |
| Open source | Apache-2.0 | Boulder (MPL-2.0) |
| Compliance | — | WebTrust, CA/B Forum |
| Best for | Certificates inside a Kubernetes cluster | Public web TLS on anything you can automate |
Choose cert-manager for certificates inside a kubernetes cluster. Choose Let's Encrypt for public web tls on anything you can automate.
* Indicative list pricing (vendor documentation and public pricing pages, August 2026).