Skip to main content
The cert-manager integration requires CXDOT Collector 1.4.0 or greater. cert-manager manages TLS certificates in Kubernetes. Use the cert-manager integration with CXDOT to collect certificate lifecycle and controller activity metrics. The cert-manager integration supports cert-manager version 1.21.1 or later.

Supported telemetry types

The cert-manager integration supports these telemetry types:

Prerequisites

Meet these requirements before configuring the integration:
  • For label-based discovery, expose each controller’s Prometheus metrics endpoint at /metrics on port 9402.
  • For Pod discovery, allow the node Collector to connect to the controller Pods.
  • For Service discovery or static targets, allow the cluster Collector to connect to each target.

Configure

To configure the cert-manager integration, follow these steps:
  1. Choose how CXDOT discovers the cert-manager controllers:
    • For controller Pods that expose port 9402, use these labels:
      • app.kubernetes.io/name: cert-manager
      • app.kubernetes.io/component: controller
    • For controller Pods or Services that require a nonstandard metrics URL, use discovery annotations.
    CXDOT creates and enables an unnamed cert-manager instance that uses discovery by default.
  2. Optional: To use static targets instead of discovery, list their host:port values in endpoints. The instance then scrapes only those targets. For example:
    Each static target resolves to http://<host>:<port>/metrics.
  3. Optional: To combine discovery and static targets, configure separate instances. The unnamed instance uses discovery, and the named instance scrapes the static targets:

Validate

  1. In the Live Telemetry Analyzer, add the following label filters:
    • Set Label to __name__ and Value to cxdot.integration.target.health.
    • Set Label to cxdot.integration.name and Value to cert_manager.
    Group the results by cxdot.integration.target, and confirm that the metric reports 1 for each target.
  2. In Metrics Explorer, run the following query:
    Confirm that the query returns a time series for each certificate condition.

Disable the cert-manager integration

Deleting every cert_manager block restores the default unnamed instance. To remove custom settings and stop collection, retain a disabled configuration:
For more information about diagnosing failed metric ingestion, see Troubleshoot ingestion.

Configuration reference

Configure one cert-manager integration instance with the following settings. In Helm values, place these settings under config.integrations.cert_manager. In a Collector configuration file, place them under cxdot.integrations.cert_manager.

Optional settings

  • enabled Type: boolean. Optional. Default: true. Whether to enable this cert-manager integration instance. If true, the Collector runs the instance. If false, the Collector doesn’t run it.
  • endpoints Type: array of object. Optional. Default: []. Static cert-manager targets. A nonempty list disables automatic discovery for this integration instance, and the Collector collects metrics from only the listed targets. Specify each target as host:port. The Collector requests http://<host>:<port>/metrics.
  • endpoints[].endpoint Type: string. Required. cert-manager target in host:port format.
  • collection_interval Type: duration. Optional. Default: 60s. How often the Collector collects metrics from each cert-manager target.
  • timeout Type: duration. Optional. Default: 60s. Maximum time allowed to collect metrics from one cert-manager target. The value must not exceed collection_interval.