Skip to content
DnsLister Forum

Where domain hunters compare notes

Finally automated SSL certificate management in Kubernetes with cert-manager + Cloudflare DNS validation

After years of manually managing SSL certificates across Kubernetes clusters, I recently moved everything to cert-manager with Cloudflare DNS-01 validation, and it has significantly reduced operational overhead.

My previous workflow looked something like this:

  • Request certificates manually
  • Verify domain ownership
  • Update Kubernetes secrets
  • Configure Ingress resources
  • Track renewal dates
  • Occasionally miss one and deal with expired certificate alerts

It worked, but it wasn't scalable.

Why I made the switch

Most of my applications run behind NGINX Ingress, and several require wildcard certificates for multiple subdomains. HTTP-01 validation wasn't always practical, especially for private services or applications behind Cloudflare.

Using cert-manager + Let's Encrypt + Cloudflare DNS, the entire process is now automated:

  1. A certificate request is created
  2. cert-manager communicates with Let's Encrypt
  3. Cloudflare automatically creates the required TXT record
  4. Domain ownership is validated
  5. Certificate is issued
  6. Renewal happens automatically before expiration

No manual DNS updates, certificate uploads, or renewal reminders.

Security considerations

Instead of using Cloudflare's Global API Key, I created a scoped API Token with only:

  • Zone → DNS → Edit
  • Zone → Zone → Read

and restricted it to a single zone.

Challenges I encountered

A few issues during setup:

  • "requires permission to list zones" → Missing Zone → Zone → Read permission.
  • Secret not found → Created the Cloudflare token secret in the wrong namespace.
  • Occasional DNS propagation delays during testing, which resolved after a short wait.

Current flow

Internet → Cloudflare DNS → cert-manager → Let's Encrypt → NGINX Ingress → Kubernetes Services → Applications

Results

  • Automatic certificate issuance
  • Automatic renewals
  • Wildcard certificate support
  • Improved security through scoped API permissions
  • Reduced operational overhead
  • Elimination of manual certificate lifecycle management

Since implementing this setup, certificate management has become a fully automated part of the Kubernetes platform. Renewals happen seamlessly in the background, Ingress resources automatically use updated certificates, and there is no longer a need to track expiration dates or perform manual certificate updates.

Overall, cert-manager combined with Cloudflare DNS validation provides a reliable and scalable approach for managing TLS certificates in Kubernetes environments, particularly when wildcard certificates and DNS-based validation are required.

Source: r/u/Pheonixsolutionstech · by /u/Pheonixsolutionstech

Leave a Reply

Your email address will not be published. Required fields are marked *