shouldiuse.io

Categories

VERDICT

Should I use Cert-manager?

Automated X.509 certificate management for Kubernetes - cert-manager.io

Worth it. If your workloads run on Kubernetes, this is the free community standard for automated TLS certificates and most clusters should just install it. If you're not on Kubernetes — a single website, a few VMs, or cloud-managed certs — skip it entirely.

Confidence

Medium. Based on 30+ public sources reviewed: Reddit practitioner threads, vendor documentation, CVE trackers, and news coverage.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityNo support evidence in sources reviewed
  • Security posture

Pricing

Free

Open source

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • Kubernetes teams with many TLS certs
  • ACME/Let's Encrypt automation at scale
  • Platform teams on OpenShift or EKS
  • Private PKI inside clusters

Not for

  • Non-Kubernetes shops — it only manages certs inside a cluster
  • Single-site owners — your host or Caddy does HTTPS free
  • Teams unwilling to maintain YAML/CRDs and cluster upgrades

Gotchas - check before you buy

high

CVE-2026-25518: controller DoS via crafted DNS responses — keep patched

medium

Let's Encrypt rate limits can stall bulk issuance

medium

Support is community-only unless you go through Venafi's commercial channel

medium

Intermediate CA expiry planning needs careful manual setup

Pros and cons

Pros

  • Free and open source — no license costs
  • Users call it a top-3 most valuable Kubernetes add-on
  • Automates Let's Encrypt issuance and renewal
  • Deep ecosystem: ServiceNow, DigiCert, GlobalSign integrations
  • Ships as a supported operator on Red Hat OpenShift

Cons

  • Confusing to learn; whole Reddit threads exist to explain it
  • Kubernetes-only; does nothing for non-cluster workloads
  • Still requires a certificate authority behind it
  • Ongoing CVE tracking and patching required

Sources & method

Analyzed 10/03/2026 - 12 sources - Actively maintained open source with a security page; several CVEs (2024–2026), mostly medium severity, patched by distro vendors.

official x3review x6security x2news x1
  • CVE-2026-25518 — cert-manager-controller DoS via crafted DNS responses, Medium-severity DoS disclosed Feb 2026 (GHSA-gx3x-vq4p-mhhv).
  • CVE-2026-62290 — Direct ACME Challenge issue, Affects specific cert-manager versions per the advisory.
  • CVE-2026-56855 — cert-manager-controller FIPS build 1.17, Listed by Snyk, Sep 2026.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 5/5. Free, open source, no license costs
  • Ease of use: 2/5. Users report confusion getting started
  • Feature depth: 4/5. Huge issuer and platform integration ecosystem
  • Support quality. No support evidence in sources reviewed
  • Security posture: 3/5. Active CVE history, vendor-patched; public security page
  • $0 Price Open source
  • Yes Free tier Fully free, open source
  • Venafi Backer Acquired creator Jetstack
  • Since 2018 In the field Earliest reviewed tutorial: Jun 2018

Pricing

Open source

Free

  • All core certificate automation features
  • Community support via GitHub

Security

Actively maintained open source with a security page; several CVEs (2024–2026), mostly medium severity, patched by distro vendors.

  • CVE-2026-25518 — cert-manager-controller DoS via crafted DNS responsesMedium-severity DoS disclosed Feb 2026 (GHSA-gx3x-vq4p-mhhv).⁸
  • CVE-2026-62290 — Direct ACME Challenge issueAffects specific cert-manager versions per the advisory.⁹
  • CVE-2026-56855 — cert-manager-controller FIPS build 1.17Listed by Snyk, Sep 2026.

What users say

Practitioners overwhelmingly treat cert-manager as essential Kubernetes infrastructure while repeatedly flagging its learning curve.

“Hot take: cert-manager is a top 3 most valuable k8s add-on”
Reddit, r/kubernetes
“I have trouble understanding cert-manager”
Reddit, r/kubernetes

Alternatives

Compare Cert-manager with each alternative.

  • Caddy

    Web server with automatic HTTPS; no Kubernetes required.

  • AWS Certificate Manager

    Managed certs if you're AWS-only; no cluster needed.

  • Cloudflare Advanced Certificate Manager

    Paid edge certs without running a cluster.

Companies that use it

  • Red Hat10
  • ServiceNow11
  • DigiCert
  • IBM
Full analysis

Based on 30+ public sources reviewed: Reddit practitioner threads, vendor documentation, CVE trackers, and news coverage.

Free, open-source TLS cert automation for Kubernetes — the default choice there; useless off-cluster.

Methodology

Based on 30+ public sources reviewed: Reddit practitioner threads, vendor documentation, CVE trackers, and news coverage.

Sources

  1. official
  2. review
  3. review
  4. review
  5. news
  6. review
  7. review
  8. security
  9. security
  10. official
  11. official
  12. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.