Leverage CyberArk LTS for cert-manager to enhance the reliability and security of your open-source cert-manager deployment. It's backed by expert-level technical support, so your platform teams can easily and efficiently scale clusters, all while safeguarding your Kubernetes workloads.
Maximize Kubernetes platform reliability and enhance security for Kubernetes machine identities with CyberArk Long Term Support (LTS) for cert-manager. As the Certificate Management solution of choice for Amazon Elastic Kubernetes Service (EKS), and Red Hat OpenShift Service for AWS (ROSA) clusters, and with native integration to Amazon Private CA and other popular Certifacte Authotities, it ensures compliance and security policy for TLS and mTLS to applications running on Kubernetes.
vice on
About cert-manager
The hugely popular cert-manager open-source project is the de facto choice for Kubernetes platform engineering teams. This solution provides highly automated machine identity management for X.509 certificate issuance and is proactively developed and maintained for the open source community by CyberArk.
Why use CyberArk LTS for cert-manager?
Organizations often require their open-source tooling to be commercially supported by a reliable vendor.
This is especially true when employing open-source software in vital business or mission-critical operations.
Using Long Term Support for cert-manager from CyberArk, engineering teams can benefit from better and more reliable levels of operation. This makes it easier for platform engineering teams to deploy and maintain cert-manager in multi-cluster production Kubernetes environments.
CyberArk LTS for cert-manager gives platform engineering teams advanced reliability for operating cert-manager across multiple Kubernetes environments, improving efficiency and minimizing the risk of platform outages. CyberArk LTS for cert-manager also comes with guaranteed response times from Venafi if a crucial bug or problem arises.
The LTS version is FIPS 140-2 compliant, and it aligns with the FedRAMP compliance program to meet all government-mandated security standards.
Key Benefits
The key benefits of using CyberArk LTS for cert-manager are:
Integration and alignment with open-source cert-manager
The strength of CyberArk's LTS version lies in its foundation, which is built and supported by the same team that maintains the cert-manager open-source project. As the original developers of cert-manager, CyberArk's experts are also the primary contributors to the open-source project, working in partnership with the Cloud Native Computing Foundation (CNCF).
This unique position ensures a seamless integration between the LTS version and the open-source project community build, allowing LTS customers to benefit from the in-depth knowledge and experience of the cert-manager team. As a result, customers can trust that the CyberArk LTS version aligns exactly with the community build which will guarantee a cohesive and consistently compatible solution.
Enhanced security
Reduce outages and improve platform security, whether operating Kubernetes on self-hosted onpremise, hybrid, or multi-cloud infrastructure.
Prioritized support for platform teams
SLA-backed support for operational peace of mind with fast-tracked bug fixes and technical advice.
Superior platform efficiency
Enhance cluster consistency where cert-manager is used as the critical solution for TLS and mTLS workload protection.
Highest-grade compliance
Provides FIPS 140-2 compliance and aligns with FedRAMP requirements to meet the highest level of government-grade standards.
Technical Features:
The following are the technical specifications and advantages of CyberArk LTS for cert-manager:
Hardened LTS build
CyberArk LTS for cert-manager provides a hardened LTS build of cert-manager fully supported for 2 years.
Dedicated repository
Customers access the Venafi LTS build from a dedicated repository provided by CyberArk.
Image validity
CyberArk signs and verifies the LTS image to ensure its authenticity and integrity.
FIPS 140-2 compliance
CyberArk ensures FIPS 140-2 compliance for the build by incorporating FIPS-certified crypto libraries as part of the LTS image.
Image deployment options
Customers can either deploy the CyberArk signed image or use the open source community build.
Community version support
CyberArk provides support for the community version based on the last 4 standard releases.
Proactive maintenance
LTS version is proactively maintained for feature parity and aligns with the most recent community build of cert-manager.
Highlights
SLA-backed support for operational peace of mind with fast-tracked bug fixes and technical advice
Provides FIPS 140-2 compliance and aligns with FedRAMP requirements to meet the highest level of government-grade standards.
CyberArk LTS for cert-manager provides a hardened LTS build of cert-manager fully supported for 2 years.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers a single pricing dimension: Long-Term Support (LTS) for cert-manager, billed per host. You commit to a contract, and your cost scales with the number of hosts you cover. cert-manager creates and renews TLS certificates for workloads in Kubernetes or OpenShift clusters. The open source project does not maintain long-term support releases, so this commercial LTS gives you extended maintenance and support beyond the standard community support window. Because pricing is host-based, adding more hosts increases your total. There are no separate tiers or add-ons to choose from.
Top-of-mind questions for buyers
What counts as one host for billing under this LTS contract?
A host is a machine running cert-manager within your Kubernetes or OpenShift cluster. Each host you cover with long-term support counts toward your total. Your cost scales with the number of hosts, so covering more hosts raises what you pay.
What does the long-term support actually cover beyond the open source project?
cert-manager's open source maintainers support each release for about four months. This commercial LTS extends that window with continued security and bug fixes for a supported release. You get maintenance on an older version longer than the community provides, so you can delay upgrades.
If I add more hosts partway through, how does that affect my charges?
Pricing is host-based, so covering additional hosts increases your total. Each host you add is billed under the same per-host rate. There are no separate tiers or add-ons; the count of covered hosts is the only factor that changes your cost.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
With CyberArk Workforce & Customer Access solutions, organizations can ensure that the right users have secure access to the right resources at the right time.
Secure, just-in-time cloud access for developers and AI agents using Zero Standing Privileges right from the CLI, IDE, or AI assistant such as Amazon Q Developer.
CyberArk Secure Cloud Access implements Zero Standing Privileges to secure identities at every layer of your multi-cloud environment without impacting native cloud user experience. Cloud admins, start a 30-day free trial today to protect cloud access and meet compliance requirements in a native, secure manner.
CyberArk Agent Guard is an AI agent security tool.
Agent Guard can be used to secure secrets retrieval for agents managed via an external secret provider, such as AWS Secrets Manager and CyberArk Secrets Manager, and traceability of AI agent MCP communications via Agent Guard MCP Proxy.
CyberArk Endpoint Privilege Manager (EPM) is an Endpoint Privilege Security solution that helps enforce role-specific least privilege for Windows, macOS and Linux workstations and servers. EPM reduces cyber risks through foundational endpoint security controls, defends against ransomware and credential compromise, and safeguards critical endpoint security agents like EDR. It streamlines operations by reducing IT Service Desk load, allowing for greater efficiency. EPM supports secure digital transformation by empowering end users with flexibility while aligning security with business goals. It also ensures audit and compliance by addressing specific regulations and creating an audit trail for endpoint identity and privilege events.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.