
cert-manager
Use cert-manager to issue and renew TLS certificates for services exposed through the Pomerium Kubernetes Ingress Controller.
Overview
cert-manager is a Kubernetes certificate controller. It can issue and renew TLS certificates for Services that the Pomerium Kubernetes Ingress Controller exposes.
Automated certificate issuance and renewal reduce manual TLS work for protected Kubernetes routes. The ownership boundary stays clear: cert-manager manages certificates, and Pomerium manages identity-aware access.
cert-manager writes TLS material to a Kubernetes Secret. The Pomerium Ingress Controller reads that Secret for the selected route. User traffic still reaches Pomerium before the protected Service.
How it works
Configure an issuer and use ingress-shim annotations or an explicit Certificate resource. Set spec.tls.secretName on the Pomerium Ingress.
Configure HTTP-01 with the Pomerium ingress class when that challenge flow fits the deployment. Current cert-manager versions prefer ingressClassName for most ingress controllers.
Keep certificate issuance, renewal status, DNS, and secret access under the Kubernetes operations process.
Example
A platform team adds a cert-manager issuer and TLS secret name to a Pomerium Ingress. cert-manager completes certificate issuance. Pomerium reads the resulting Kubernetes TLS Secret and serves the protected route.
Considerations
- cert-manager issues certificates. It does not authenticate users or enforce Pomerium policy.
- Pomerium reads the TLS Secret. It does not replace cert-manager as the certificate controller.
- This integration applies to the Kubernetes Ingress deployment path.
