SSL management: no more outages caused by an expired certificate
Discover every certificate in the estate, including the ones nobody documented, renew them automatically, and get warned in weeks rather than hours.
What is SSL Management?
DevOpsArk SSL management is the module that discovers, monitors, renews and reports on TLS certificates across Kubernetes ingresses, load balancers, servers and public endpoints.
What SSL Management is for
The conditions this module removes. If none of these are familiar, you probably do not need it yet.
- A certificate nobody knew about expires and takes a service down on a Saturday.
- Certificates are issued by three different processes and tracked in none of them.
- Renewal reminders go to a mailbox belonging to someone who left.
- The internal certificate authority issues certificates that no inventory records.
- Weak protocol versions and cipher suites persist because nobody audits endpoints.
SSL management discovers certificates from three directions at once: Kubernetes ingress and Secret resources, cloud load balancers and certificate services, and direct probing of the endpoints in your inventory, which is how it finds the certificates that were never recorded anywhere. Each certificate is tracked with its issuer, subject alternative names, expiry, the endpoints presenting it and the team that owns the service behind it. Renewal is automated where an ACME issuer such as Let us Encrypt or an internal certificate authority can be used, and coordinated with the load balancer or ingress so the new certificate is in place before the old one lapses. Where renewal must remain manual, escalating notifications begin weeks ahead and go to the owning team rather than to a mailbox. The same endpoint probing reports protocol versions, cipher suites and chain problems, so certificate hygiene is measured rather than assumed.
What SSL Management does
The 6 capabilities that make up SSL Management.
Certificate discovery
From Kubernetes resources, cloud load balancers and certificate services, and by probing endpoints directly to find undocumented certificates.
Automated renewal
ACME and internal certificate authority issuance, coordinated with ingresses and load balancers so the new certificate is installed before expiry.
Escalating expiry alerts
Notifications begin weeks ahead and escalate, routed to the team that owns the service rather than a shared mailbox.
Protocol and cipher audit
Reports weak TLS versions, deprecated cipher suites, incomplete chains and hostname mismatches per endpoint.
Wildcard and SAN tracking
Understands which services depend on a shared wildcard or multi-domain certificate, so its renewal blast radius is known.
Certificate inventory
One list of every certificate with issuer, expiry, owner and the endpoints presenting it.
How SSL Management fits together
Outcomes
- Expiry-driven outages stop, because discovery covers the certificates nobody documented.
- Renewal happens automatically wherever an issuer is available.
- Warnings reach the team that can act, weeks ahead.
- Weak TLS configuration is measured continuously instead of at audit time.
- The blast radius of a shared wildcard certificate is known before it is renewed.
Using SSL Management, step by step
The path from connecting a source to getting value, in the order it happens.
- 1Discover
Certificates are found from Kubernetes, cloud services and direct endpoint probing.
- 2Attribute
Each certificate is linked to its endpoints and the owning team.
- 3Automate renewal
ACME or internal CA issuance is configured where possible.
- 4Install and verify
The new certificate is installed and the endpoint is probed to confirm.
- 5Audit continuously
Protocol versions, cipher suites and chains are checked on a schedule.
Where teams apply SSL Management
Eliminate expiry outages
Discover every certificate, automate renewal where possible and escalate the rest early.
Audit TLS configuration
Report weak protocol versions and cipher suites across all public and internal endpoints.
Standardise issuance
Route all issuance through one automated path instead of three ad-hoc processes.
Evidence certificate control
Produce the certificate inventory with issuer, expiry and owner on request.
What SSL Management works with
Named integrations link to their own page. The rest are supported runtimes and formats.
SSL Management: frequently asked questions
The 7 questions teams ask most often before adopting SSL Management.
SSL certificate management is the discovery, tracking, renewal and auditing of the TLS certificates that secure your endpoints. It exists because certificates expire, and an expired certificate takes a service down as effectively as a crash.
By probing the endpoints in your infrastructure inventory directly, in addition to reading Kubernetes resources and cloud certificate services. Direct probing is what surfaces certificates issued outside any recorded process.
Any ACME-compatible authority, including Let's Encrypt, plus internal certificate authorities and the cloud providers' own certificate services.
It is tracked with escalating notifications that begin weeks before expiry and are routed to the team owning the service, rather than to a shared mailbox. The record shows what manual step is required.
Yes. Endpoint probing reports protocol versions, cipher suites, chain completeness and hostname mismatches, so weak configuration is found continuously rather than at audit time.
A wildcard or multi-domain certificate is tracked with the full list of services depending on it, so its renewal blast radius is known before the renewal rather than discovered during it.
Yes. Certificates issued by cert-manager are discovered and tracked in the same inventory, and DevOpsArk can report on cert-manager health rather than replacing it.
See SSL Management against your own environment
A 30-minute walkthrough with a platform engineer, not a sales deck. Bring a cluster and a problem.