Skip to main content
Licensed guide

Rotate certificates with cert-manager

Manually trigger certificate rotation across platform services using cert-manager — including wildcard TLS, Istio mTLS certs, and Vault PKI intermediate CA renewal.

This guide includes:

  • Checking certificate expiry status via the Console (Tools → cert-manager) and kubectl
  • Manually triggering rotation for wildcard TLS certificates
  • Rotating Istio mTLS workload certificates without service interruption
  • Renewing Vault PKI intermediate CA and propagating to dependent services
  • Verifying rotation success and clearing browser certificate caches
  • Setting up Platform Custodian alerts for certificates approaching expiry