Marcio Cunha

X.509 Certificate Lifecycle Management in Kubernetes with ACME and Vault

Learn how to automate digital certificate issuance and renewal in Kubernetes clusters using the ACME protocol integrated with HashiCorp Vault for seamless security.

Marcio Cunha•3 min
Also available in:PortuguêsEspañol
Summary
  • Automating certificate lifecycles eliminates operational failures caused by manual oversights or forgotten expirations.
  • Integrating cert-manager with HashiCorp Vault centralizes private key custody with strong logical isolation.
  • The ACME protocol streamlines communication with public and private certificate authorities without exposing access tokens.
  • Rigorous issuance policies in Vault prevent compromised workloads from generating unauthorized certificates.
  • Continuous observability of certificate status prevents downtime in large-scale production environments.

The Operational Challenge of Encryption in High-Density Environments

Managing the security of dozens or hundreds of microservices in a Kubernetes cluster requires much more than just installing initial digital certificates. In practice, this means dealing with credentials that periodically expire, demanding repetitive processes which, when done manually, pave the way for catastrophic human errors. When a certificate expires in production, encrypted communication between applications breaks instantly, causing outages and disrupting service to users.

To eliminate this operational Achilles' heel, modern engineering relies on end-to-end automation systems. Instead of depending on calendar reminders or ad-hoc scripts, infrastructure must handle the entire certificate lifecycle—from private key generation to revocation and replacement before expiration. This is where established market tools come into play, combining standardized issuance protocols with secure credential vaults.

Understanding the Pillars: ACME, Vault, and the Kubernetes Ecosystem

The acronym ACME refers to an open protocol designed to automate the exchange of digital certificates between servers and certificate authorities, such as Let's Encrypt. It acts as a digital messenger that proves you control an internet domain before issuing a valid certificate, all in an automated fashion without human bureaucracy. This mechanics eliminates the need to manually purchase and install certificate files on every single web server.

On the other hand, HashiCorp Vault acts as a heavily shielded digital safe, specialized in storing corporate secrets, passwords, API keys, and sensitive certificates. In an enterprise scenario, we cannot always rely exclusively on public authorities to issue internal certificates; we often need a private Certificate Authority. Vault assumes this role internally, ensuring that keys remain protected against leaks and unauthorized access.

Solution Architecture: Integrating Cert-Manager, ACME, and HashiCorp Vault

Within the Kubernetes ecosystem, the cert-manager operator acts as the conductor leading the dance of digital certificates. It constantly observes cluster resources and requests new certificates whenever it notices a credential is about to expire. By integrating cert-manager with HashiCorp Vault using the ACME protocol, we create a secure bridge where Vault can act either as a direct issuer or as a request validator.

In practice, this architecture decentralizes operational risk and centralizes security policy control. Cert-manager talks to Vault via rigorous authentication tokens, ensuring only authorized namespaces can request specific types of certificates. If an attacker gains access to an isolated pod, they will lack the autonomy to generate corrupted or fake certificates for the rest of the corporate infrastructure.

Practical Implementation and Cluster Resource Configuration

To get this machinery running, the first step involves configuring the issuer in Kubernetes, instructing cert-manager on how to connect to the Vault vault. Below is an example manifest defining a ClusterIssuer utilizing Vault as an ACME-based issuance backend:

apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
  name: vault-issuer
spec:
  vault:
    server: https://vault.internal.net:8200
    path: pki
    auth:
      kubernetes:
        role: cert-manager
        path: kubernetes

With the issuer configured, the next step is creating a Certificate resource pointing to the newly created issuer. Cert-manager will interpret this manifest, generate the certificate signing request, and interact with Vault to obtain the final cryptographic artifact, automatically injecting it into a Kubernetes secret for application use.

apiVersion: cert-manager.io/v1
kind: Certificate
metadata:
  name: app-tls-certificate
  namespace: production
spec:
  secretName: app-tls-secret
  duration: 2160h # 90 days
  renewBefore: 360h # 15 days before
  issuerRef:
    name: vault-issuer
    kind: ClusterIssuer
  dnsNames:
  - myapp.enterprise.net

Monitoring, Validation, and Troubleshooting Common Failures

Implementing automation does not mean abandoning vigilance over running systems. It is essential to actively monitor metrics exposed by cert-manager to identify Vault communication failures or renewal issues before they impact the production environment. Observability tools like Prometheus collect these metrics and trigger alerts if any certificate approaches expiration without successful renewal.

Among the most common issues in daily operations are expiring Kubernetes service tokens used by cert-manager and network connectivity failures caused by restrictive firewall policies. Maintaining audit routines on Vault logs and periodically checking TLS connection health ensures infrastructure remains resilient and proof against unwanted surprises.

Final Thoughts

The combined adoption of ACME, cert-manager, and HashiCorp Vault in Kubernetes clusters represents a mature leap in security readiness for any engineering organization. By eliminating manual processes and shielding cryptographic key storage, teams gain delivery speed without sacrificing compliance and protection against incidents. Investing in this automation prepares infrastructure to scale smoothly and robustly.