About This Architecture

ROSA Cert-Manager Vault Integration automates TLS certificate issuance and renewal across OpenShift on AWS using HashiCorp Vault as a centralized PKI backend. The architecture connects cert-manager's ClusterIssuer to Vault's PKI Secrets Engine via Kubernetes authentication, enabling secure certificate provisioning for ingress, service mesh, and application workloads. Platform admins configure Vault once; cert-manager controllers and renewal processes handle ongoing certificate management without manual intervention. Fork this diagram on Diagrams.so to customize namespace layouts, add additional certificate use cases, or integrate with your existing Vault infrastructure. This pattern eliminates certificate sprawl and ensures compliance with centralized CA policies across all cluster workloads.

People also ask

How do I automate TLS certificate management for ingress, service mesh, and applications on ROSA using cert-manager and Vault?

This diagram shows a complete cert-manager and Vault integration on ROSA where Vault acts as the centralized PKI backend. The ClusterIssuer connects to Vault's PKI Secrets Engine via Kubernetes authentication, automatically issuing and renewing certificates for ingress (HAProxy Router), service mesh sidecars, and application pods across multiple namespaces.

ROSA Cert-Manager Vault Integration

KubernetesadvancedROSAcert-managerHashiCorp VaultPKITLS certificates
Domain: KubernetesAudience: Kubernetes platform engineers managing certificate lifecycle on ROSA clusters
1 views0 favoritesPublic

Created by

August 12, 2026

Updated

August 13, 2026 at 1:57 AM

Type

architecture

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI

AI-generated. Verify before production use. Learn more

Report this diagram