Ssl Certificate Management

by aj-geddes3f5182cfd739No license355 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 7 months ago

Manage SSL/TLS certificates with automated provisioning, renewal, and monitoring using Let's Encrypt, ACM, or Vault.

Includes scriptsDevOps & CloudSecurity
AI-generated overview

Guides automated SSL/TLS certificate provisioning, renewal, monitoring and secure distribution across infrastructure.

What it does
Provides reference guides and a starter configuration for managing SSL/TLS certificates, covering Let's Encrypt with cert-manager, AWS ACM, automated renewal, monitoring and certificate pinning. It includes a YAML config starter and a validation script for checking configuration. The material is advisory documentation rather than an executable certificate manager.
When to use it
Use when enabling HTTPS/TLS, automating certificate renewal, handling multi-domain or wildcard certificates, monitoring expiration, or planning zero-downtime rotation and internal PKI.
Requirements
An agent that can read the reference documents and templates; the bundled shell script requires a shell environment. Following the guides assumes access to certificate tooling such as cert-manager, Let's Encrypt, AWS ACM or Vault, plus the relevant cloud or DNS credentials and network access.

SSL Certificate Management

Table of Contents

Overview

Implement automated SSL/TLS certificate management across infrastructure, including provisioning, renewal, monitoring, and secure distribution to services.

When to Use

  • HTTPS/TLS enablement
  • Certificate renewal automation
  • Multi-domain certificate management
  • Wildcard certificate handling
  • Certificate monitoring and alerts
  • Zero-downtime certificate rotation
  • Internal PKI management

Quick Start

Minimal working example:

yaml
# cert-manager-setup.yamlapiVersion: cert-manager.io/v1kind: ClusterIssuermetadata:  name: letsencrypt-prodspec:  acme:    server: https://acme-v02.api.letsencrypt.org/directory    email: [email protected]    privateKeySecretRef:      name: letsencrypt-prod    solvers:      # HTTP-01 solver for standard domains      - http01:          ingress:            class: nginx        selector:          dnsNames:            - "myapp.com"            - "www.myapp.com"
      # DNS-01 solver for wildcard domains      - dns01:          route53:            region: us-east-1// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
Let's Encrypt with Cert-Manager [blocked]Let's Encrypt with Cert-Manager
AWS ACM Certificate Management [blocked]AWS ACM Certificate Management
Certificate Monitoring and Renewal [blocked]Certificate Monitoring and Renewal
Automated Certificate Renewal [blocked]Automated Certificate Renewal
Certificate Pinning [blocked]Certificate Pinning

Best Practices

✅ DO

  • Automate certificate renewal
  • Use Let's Encrypt for public certs
  • Monitor certificate expiration
  • Use wildcard certs strategically
  • Implement certificate pinning
  • Rotate certificates regularly
  • Store keys securely
  • Use strong key sizes (2048+ RSA, 256+ ECDSA)

❌ DON'T

  • Manual certificate management
  • Self-signed certs in production
  • Share private keys
  • Ignore expiration warnings
  • Use weak key sizes
  • Mix dev and prod certs
  • Commit certs to git
  • Disable certificate validation

Source and attribution

Source:aj-geddes/useful-ai-promptsinskills/ssl-certificate-managementat commit3f5182c

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal