рдореБрдЦреНрдп рдордЬрдХреБрд░рд╛рдХрдбреЗ рдЬрд╛
JobCannon
рд╕рд░реНрд╡ рдХреМрд╢рд▓реНрдпреЗ

Cert Manager & ACME

Automate SSL/TLS certificate lifecycle on Kubernetes with Let's Encrypt

тмв рд╢реНрд░реЗрдгреА 2рддрд╛рдВрддреНрд░рд┐рдХ
+$20k-
рдкрдЧрд╛рд░рд╛рд╡рд░реАрд▓ рдкрд░рд┐рдгрд╛рдо
3 рдорд╣рд┐рдиреЗ
рд╢рд┐рдХрдгреНрдпрд╛рд╕ рд▓рд╛рдЧрдгрд╛рд░рд╛ рд╡реЗрд│
рдордзреНрдпрдо
рдХрд╛рдард┐рдгреНрдп
тАФ
рдХрд░рд┐рдЕрд░реНрд╕
рдПрдХрд╛ рджреГрд╖реНрдЯрд┐рдХреНрд╖реЗрдкрд╛рдд

Cert Manager is the Kubernetes community standard for automating X.509 certificate lifecycle. ACME (Automated Certificate Management Environment) is the protocol cert-manager uses to talk to Let's Encrypt (free) or other CAs. Core use: automatic renewal before expiration, multi-cert environments, wildcard certificates. Mastery takes 2-3 months for DevOps engineers. Typical salary impact: $15-30k for platform engineers who own cert ops.

Cert Manager & ACME рдореНрд╣рдгрдЬреЗ рдХрд╛рдп

Cert-manager is the Kubernetes standard for automating X.509 certificate management. Never manually renew SSL certs again. Integrated with Ingress for transparent HTTPS. Boost: +$20k-$40k

ЁЯФз рд╕рд╛рдзрдиреЗ рдЖрдгрд┐ рдкрд░рд┐рд╕рдВрд╕реНрдерд╛
cert-manager Kubernetes operatorLet's Encrypt ACMEKubernetes manifests (YAML)OpenSSL (certificate inspection)Helm charts (deployment)Automated renewal schedulingIssuer/ClusterIssuer resourcesDNS-01 challenge validation

ЁЯТ░ рдкреНрд░рджреЗрд╢рд╛рдиреБрд╕рд╛рд░ рдкрдЧрд╛рд░

рдкреНрд░рджреЗрд╢рдЬреНрдпреБрдирд┐рдпрд░рдордзреНрдпрдорд╕реАрдирд┐рдпрд░
USA$70k$130k$185k
UK┬г55k┬г105k┬г155k
EUтВм60kтВм115kтВм165k
CANADAC$85kC$155kC$220k

тЪЦ рдпрд╛рдВрдЪреНрдпрд╛рд╢реА рддреБрд▓рдирд╛ рдХрд░рд╛

тЭУ FAQ

What's cert-manager and why not just buy certificates?
Cert-manager automates renewal so you never forget. Bought certs expire in 1-3 years; you must manually renew. Let's Encrypt certs expire in 90 days but auto-renew. Cert-manager handles both. On Kubernetes, cert-manager integrates with Ingress (automagically sets TLS) and integrates with Let's Encrypt ACME.
Is Let's Encrypt free really free?
Yes, fully free (donated by EFF, Mozilla, etc.). Rate-limited: 50 certificates per domain per week. Perfect for most teams. Wildcard certs also free. Downside: no phone support, basic validation only. Enterprise CAs (DigiCert, Entrust) cost $200-1000/year but offer phone support and higher validation.
How often does cert-manager renew certificates?
Default: renew 30 days before expiration. Let's Encrypt certs expire 90 days after issue, so renewal happens at day ~60. You can customize this (earlier renewal for peace of mind). Failed renewals auto-retry. If manual intervention needed, cert-manager sends alerts.
Can cert-manager manage non-Kubernetes certificates?
Not natively. Cert-manager runs as Kubernetes operator; it manages certs as K8s resources. For non-K8s apps, use cert-manager to generate cert (stored as Secret), then manually copy to app server. Or use Vault (alternative CA) for broader infrastructure.
What's the difference between HTTP-01 and DNS-01 challenges?
HTTP-01: ACME server validates by accessing .well-known/acme-challenge/{token} on your domain. Requires public HTTP access. Faster, simpler. DNS-01: ACME server checks DNS TXT record for token. Requires DNS API access. Enables wildcard certs, works behind firewalls. Pick based on your setup; most teams use HTTP-01.
How do I debug a failed certificate renewal?
Check cert-manager logs: kubectl logs -n cert-manager deploy/cert-manager. Look for ACME challenge failures. Common: DNS misconfiguration, firewall blocking HTTP-01, rate limits hit. Inspect Certificate resource: kubectl describe cert <name>. View Issuer status. Most failures = network connectivity, not cert-manager bugs.
What salary jump for cert-manager expertise?
Platform engineer ($100-130k) тЖТ cert-manager + PKI specialist ($130-160k). Rare skill: only 30% of K8s teams automate certs fully. Managing certs for 500+ microservices = premium compensation. Senior (architecture): $160-200k.

рд╣реЗ рдХреМрд╢рд▓реНрдп рддреБрдордЪреНрдпрд╛рд╕рд╛рдареА рдпреЛрдЧреНрдп рдЖрд╣реЗ рдХрд╛, рдпрд╛рдЪреА рдЦрд╛рддреНрд░реА рдирд╛рд╣реА?

рдХрд░рд┐рдЕрд░ рдореЕрдЪ рдХрд░реВрди рдкрд╛рд╣рд╛ тАФ рдЖрдореНрд╣реА рдпреЛрдЧреНрдп рдорд╛рд░реНрдЧ рд╕реБрдЪрд╡реВ.

рдорд╛рдЭреНрдпрд╛рд╕рд╛рдареА рд╕рд░реНрд╡реЛрддреНрддрдо рдХреМрд╢рд▓реНрдпреЗ рд╢реЛрдзрд╛ тЖТ

рддреБрдордЪрд╛ рдЖрджрд░реНрд╢ рдХрд░рд┐рдЕрд░ рдорд╛рд░реНрдЧ рд╢реЛрдзрд╛

реи,релреирез рдХрд░рд┐рдЕрд░рдордзреНрдпреЗ рдХреМрд╢рд▓реНрдпрд╛рдВрд╡рд░ рдЖрдзрд╛рд░рд┐рдд рдЬреБрд│рдгреА. рдореЛрдлрдд, ~3 рдорд┐рдирд┐рдЯреЗ.

рдХрд░рд┐рдЕрд░ рдореЕрдЪ рдХрд░реВрди рдкрд╛рд╣рд╛ тАФ рдореЛрдлрдд тЖТ