Skip to main content
See All Integrations

cert-manager

Use cert-manager to issue and renew TLS certificates for services exposed through the Pomerium Kubernetes Ingress Controller.

First-party Pomerium Kubernetes guide

Category
Cloud Native Tools

Overview

cert-manager is a Kubernetes certificate controller. It can issue and renew TLS certificates for Services that the Pomerium Kubernetes Ingress Controller exposes.

Automated certificate issuance and renewal reduce manual TLS work for protected Kubernetes routes. The ownership boundary stays clear: cert-manager manages certificates, and Pomerium manages identity-aware access.

cert-manager writes TLS material to a Kubernetes Secret. The Pomerium Ingress Controller reads that Secret for the selected route. User traffic still reaches Pomerium before the protected Service.

How it works

Configure an issuer and use ingress-shim annotations or an explicit Certificate resource. Set spec.tls.secretName on the Pomerium Ingress.

Configure HTTP-01 with the Pomerium ingress class when that challenge flow fits the deployment. Current cert-manager versions prefer ingressClassName for most ingress controllers.

Keep certificate issuance, renewal status, DNS, and secret access under the Kubernetes operations process.

Example

A platform team adds a cert-manager issuer and TLS secret name to a Pomerium Ingress. cert-manager completes certificate issuance. Pomerium reads the resulting Kubernetes TLS Secret and serves the protected route.

Considerations

  • cert-manager issues certificates. It does not authenticate users or enforce Pomerium policy.
  • Pomerium reads the TLS Secret. It does not replace cert-manager as the certificate controller.
  • This integration applies to the Kubernetes Ingress deployment path.

Sources and official resources

  • Use the official Pomerium Ingress Controller to convert selected Kubernetes Ingress resources into TLS routes with identity-aware policy.

  • Run the Pomerium Kubernetes Ingress Controller on Amazon EKS and keep application Services private behind explicit Pomerium Ingress resources.

  • Put the Argo Workflows UI and API behind Pomerium so users pass identity-aware route policy before traffic reaches Argo Server.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo