Supported telemetry types
The cert-manager integration supports these telemetry types:Prerequisites
Meet these requirements before configuring the integration:- For label-based discovery, expose each controller’s
Prometheus metrics endpoint
at
/metricson port9402. - For Pod discovery, allow the node Collector to connect to the controller Pods.
- For Service discovery or static targets, allow the cluster Collector to connect to each target.
Configure
To configure the cert-manager integration, follow these steps:-
Choose how CXDOT discovers the cert-manager controllers:
-
For controller Pods that expose port
9402, use these labels:app.kubernetes.io/name: cert-managerapp.kubernetes.io/component: controller
- For controller Pods or Services that require a nonstandard metrics URL, use discovery annotations.
-
For controller Pods that expose port
-
Optional: To use static targets instead of discovery, list their
host:portvalues inendpoints. The instance then scrapes only those targets. For example:Each static target resolves tohttp://<host>:<port>/metrics. -
Optional: To combine discovery and static targets, configure separate instances.
The unnamed instance uses discovery, and the named instance scrapes the static
targets:
Validate
-
In the
Live Telemetry Analyzer,
add the following label filters:
- Set Label to
__name__and Value tocxdot.integration.target.health. - Set Label to
cxdot.integration.nameand Value tocert_manager.
cxdot.integration.target, and confirm that the metric reports1for each target. - Set Label to
-
In
Metrics Explorer,
run the following query:
Confirm that the query returns a time series for each certificate condition.
Disable the cert-manager integration
Deleting everycert_manager block restores the default unnamed instance. To remove
custom settings and stop collection, retain a disabled configuration:
Configuration reference
Configure one cert-manager integration instance with the following settings. In Helm values, place these settings underconfig.integrations.cert_manager. In a Collector configuration
file, place them under cxdot.integrations.cert_manager.
Optional settings
-
enabledType:boolean. Optional. Default:true. Whether to enable this cert-manager integration instance. If true, the Collector runs the instance. If false, the Collector doesn’t run it. -
endpointsType:array of object. Optional. Default:[]. Static cert-manager targets. A nonempty list disables automatic discovery for this integration instance, and the Collector collects metrics from only the listed targets. Specify each target ashost:port. The Collector requestshttp://<host>:<port>/metrics. -
endpoints[].endpointType:string. Required. cert-manager target inhost:portformat. -
collection_intervalType:duration. Optional. Default:60s. How often the Collector collects metrics from each cert-manager target. -
timeoutType:duration. Optional. Default:60s. Maximum time allowed to collect metrics from one cert-manager target. The value must not exceedcollection_interval.