Install an ACME SSL Certificate in Kubernetes
-
SSL certificates can be completely automated using ACME within Kubernetes. The best method for installing an ACME SSL certificate in Kubernetes will vary depending on your specific setup/configuration. This page will provides guidance and tips to help you configure ACME SSL in your context.
-
-
*
The Basics
- Certificates and keys typically live inside Kubernetes as Secrets
- SSL certificates are typically configured as part of the ingress controller, for example NGINX Ingress Controller, Traefik, etc.
- In some cases, the SSL certificate may be configured outside of Kubernetes (e.g. at a load balancer).
-
*
Choose an ACME Client for Kubernetes
The most popular ACME client for Kubernetes is cert-manager: https://cert-manager.io/
If you're using Traefik, it has built-in support for ACME: https://doc.traefik.io/traefik/https/acme/
Reminder: Be sure that you’re using the EAB credentials provided by the CA (i.e. Sectigo or DigiCert) when setting up ACME.
-
*
Tutorial: Configure ACME SSL in Kubernetes
Follow this tutorial from DigiCert for setting up ACME SSL certificates in Kubernetes: Configure cert-manager and ACME with Kubernetes
-
*
Need Help?
Please contact our Support Team for any questions related to ACME for Kubernetes.
-