Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Certificate renewal: verify the served certificate after issuance

Last updated: 5 Oct 20266 min read
tutorial
AdvancedBy AITrove Editorial

Certificate renewal replaces an expiring certificate before clients reject it. In Kubernetes, a certificate controller may update a Secret successfully while an ingress or application still serves the old certificate. The operational unit is the entire path from issuance through reload to the hostname seen by clients, including private-key access and any intermediate chain.

Operational decision

A parcel gateway terminates TLS for a customer-facing hostname. Create a Certificate resource using an existing approved issuer, set the expected DNS name, and alert with enough time to investigate failures before expiry. The fragment names a Secret for the gateway to consume; it assumes the issuer and gateway wiring already exist. In a test environment, trigger a renewal through the controller's supported mechanism, inspect the new certificate's validity, then connect to the external hostname and verify which certificate is actually served. Confirm that a reload does not cut active connections beyond the service target. If the gateway caches the old Secret, fix its reload path rather than repeatedly deleting and recreating credentials. Protect the private key with narrow namespace access and backup rules that match the issuer model.

yaml
apiVersion: cert-manager.io/v1
kind: Certificate
metadata: {name: parcel-edge, namespace: parcels}
spec:
  secretName: parcel-edge-tls
  dnsNames: [parcels.internal.example]
  issuerRef:
    name: parcel-edge-issuer
    kind: Issuer

Cost and verification

Automatic issuance reduces routine manual work but adds controller, DNS or challenge, and gateway dependencies. A certificate can be Ready while the client still sees an expired one. Monitor expiry from outside the cluster as well as controller status. Renewal may rotate keys and trigger a rollout; test how that affects long-lived connections and pinning clients. The hostname is illustrative. Do not assume a Secret update reaches every edge replica at the same instant.

Common Mistakes

  • Do not equate Certificate Ready with a successful client handshake.
  • Do not delete the TLS Secret as the default rotation procedure.
  • Do not log or broadly copy private-key material.

Connected lessons

Practice and check

Advanced follow-up

TLS trust operations follow-up

Browser and edge security follow-up

devops
operations
Storage details