Vai al contenuto principale
JobCannon
Tutte le competenze

Cert Manager & ACME

Automate SSL/TLS certificate lifecycle on Kubernetes with Let's Encrypt

⬢ LIVELLO 2Tecniche
+$20k-
Impatto sullo stipendio
3 mesi
Tempo di apprendimento
Medio
Difficoltà
—
Carriere
In sintesi

Cert Manager is the Kubernetes community standard for automating X.509 certificate lifecycle. ACME (Automated Certificate Management Environment) is the protocol cert-manager uses to talk to Let's Encrypt (free) or other CAs. Core use: automatic renewal before expiration, multi-cert environments, wildcard certificates. Mastery takes 2-3 months for DevOps engineers. Typical salary impact: $15-30k for platform engineers who own cert ops.

Cos'è Cert Manager & ACME

Cert-manager is the Kubernetes standard for automating X.509 certificate management. Never manually renew SSL certs again. Integrated with Ingress for transparent HTTPS. Boost: +$20k-$40k

🔧 STRUMENTI ED ECOSISTEMA
cert-manager Kubernetes operatorLet's Encrypt ACMEKubernetes manifests (YAML)OpenSSL (certificate inspection)Helm charts (deployment)Automated renewal schedulingIssuer/ClusterIssuer resourcesDNS-01 challenge validation

💰 Stipendio per regione

RegioneLivello baseMidLivello esperto
USA$70k$130k$185k
UK£55k£105k£155k
EU€60k€115k€165k
CANADAC$85kC$155kC$220k

❓ Domande frequenti

What's cert-manager and why not just buy certificates?
Cert-manager automates renewal so you never forget. Bought certs expire in 1-3 years; you must manually renew. Let's Encrypt certs expire in 90 days but auto-renew. Cert-manager handles both. On Kubernetes, cert-manager integrates with Ingress (automagically sets TLS) and integrates with Let's Encrypt ACME.
Is Let's Encrypt free really free?
Yes, fully free (donated by EFF, Mozilla, etc.). Rate-limited: 50 certificates per domain per week. Perfect for most teams. Wildcard certs also free. Downside: no phone support, basic validation only. Enterprise CAs (DigiCert, Entrust) cost $200-1000/year but offer phone support and higher validation.
How often does cert-manager renew certificates?
Default: renew 30 days before expiration. Let's Encrypt certs expire 90 days after issue, so renewal happens at day ~60. You can customize this (earlier renewal for peace of mind). Failed renewals auto-retry. If manual intervention needed, cert-manager sends alerts.
Can cert-manager manage non-Kubernetes certificates?
Not natively. Cert-manager runs as Kubernetes operator; it manages certs as K8s resources. For non-K8s apps, use cert-manager to generate cert (stored as Secret), then manually copy to app server. Or use Vault (alternative CA) for broader infrastructure.
What's the difference between HTTP-01 and DNS-01 challenges?
HTTP-01: ACME server validates by accessing .well-known/acme-challenge/{token} on your domain. Requires public HTTP access. Faster, simpler. DNS-01: ACME server checks DNS TXT record for token. Requires DNS API access. Enables wildcard certs, works behind firewalls. Pick based on your setup; most teams use HTTP-01.
How do I debug a failed certificate renewal?
Check cert-manager logs: kubectl logs -n cert-manager deploy/cert-manager. Look for ACME challenge failures. Common: DNS misconfiguration, firewall blocking HTTP-01, rate limits hit. Inspect Certificate resource: kubectl describe cert <name>. View Issuer status. Most failures = network connectivity, not cert-manager bugs.
What salary jump for cert-manager expertise?
Platform engineer ($100-130k) → cert-manager + PKI specialist ($130-160k). Rare skill: only 30% of K8s teams automate certs fully. Managing certs for 500+ microservices = premium compensation. Senior (architecture): $160-200k.

Non sei sicuro che questa competenza faccia per te?

Fai il Career Match — ti suggeriremo i percorsi giusti.

Trova le competenze adatte a te →

Trova il tuo percorso di carriera ideale

Abbinamento basato sulle competenze per 2521 carriere. Gratis, ~3 minuti.

Fai il Career Match — gratis →