After years of manually managing SSL certificates across Kubernetes clusters, I recently moved everything to cert-manager with Cloudflare DNS-01 validation, and it has significantly reduced operational overhead.
My previous workflow looked something like this:
- Request certificates manually
- Verify domain ownership
- Update Kubernetes secrets
- Configure Ingress resources
- Track renewal dates
- Occasionally miss one and deal with expired certificate alerts
It worked, but it wasn't scalable.
Why I made the switch
Most of my applications run behind NGINX Ingress, and several require wildcard certificates for multiple subdomains. HTTP-01 validation wasn't always practical, especially for private services or applications behind Cloudflare.
Using cert-manager + Let's Encrypt + Cloudflare DNS, the entire process is now automated:
- A certificate request is created
- cert-manager communicates with Let's Encrypt
- Cloudflare automatically creates the required TXT record
- Domain ownership is validated
- Certificate is issued
- Renewal happens automatically before expiration
No manual DNS updates, certificate uploads, or renewal reminders.
Security considerations
Instead of using Cloudflare's Global API Key, I created a scoped API Token with only:
- Zone → DNS → Edit
- Zone → Zone → Read
and restricted it to a single zone.
Challenges I encountered
A few issues during setup:
- "requires permission to list zones" → Missing Zone → Zone → Read permission.
- Secret not found → Created the Cloudflare token secret in the wrong namespace.
- Occasional DNS propagation delays during testing, which resolved after a short wait.
Current flow
Internet → Cloudflare DNS → cert-manager → Let's Encrypt → NGINX Ingress → Kubernetes Services → Applications
Results
- Automatic certificate issuance
- Automatic renewals
- Wildcard certificate support
- Improved security through scoped API permissions
- Reduced operational overhead
- Elimination of manual certificate lifecycle management
Since implementing this setup, certificate management has become a fully automated part of the Kubernetes platform. Renewals happen seamlessly in the background, Ingress resources automatically use updated certificates, and there is no longer a need to track expiration dates or perform manual certificate updates.
Overall, cert-manager combined with Cloudflare DNS validation provides a reliable and scalable approach for managing TLS certificates in Kubernetes environments, particularly when wildcard certificates and DNS-based validation are required.
Source: r/u/Pheonixsolutionstech · by /u/Pheonixsolutionstech