> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# cert-manager

> Certificate lifecycle and expiry metrics from cert-manager, scraped from its controller's Prometheus endpoint.

The cert-manager integration requires CXDOT Collector 1.4.0 or greater.

[cert-manager](https://cert-manager.io/) manages TLS certificates in Kubernetes. Use the
cert-manager integration with
[CXDOT](https://docs-xcor.paloaltonetworks.com/ingest/xcor/integrations/collector)
to collect certificate lifecycle and controller activity metrics.

The cert-manager integration supports cert-manager version 1.21.1 or later.

## Supported telemetry types

The cert-manager integration supports these telemetry types:

| Type | Supported |
| - | - |
| Logs | No |
| Metrics | Yes |
| Traces | No |
| Events | No |

## Prerequisites

Meet these requirements before configuring the integration:

* For label-based discovery, expose each controller's
  [Prometheus metrics endpoint](https://cert-manager.io/docs/devops-tips/prometheus-metrics/)
  at `/metrics` on port `9402`.
* For Pod discovery, allow the node Collector to connect to the controller Pods.
* For Service discovery or static targets, allow the cluster Collector to connect
  to each target.

## Configure

To configure the cert-manager integration, follow these steps:

1. Choose how CXDOT discovers the cert-manager controllers:

   * For controller Pods that expose port `9402`, use these labels:

     * `app.kubernetes.io/name: cert-manager`
     * `app.kubernetes.io/component: controller`

   * For controller Pods or Services that require a nonstandard metrics URL, use
     discovery annotations.

   CXDOT creates and enables an unnamed cert-manager instance that uses discovery
   by default.

2. Optional: To use static targets instead of discovery, list their `host:port`
   values in `endpoints`. The instance then scrapes only those targets. For example:

   ```yaml theme={null}
   config:
     integrations:
       cert_manager:
         endpoints:
           - endpoint: 10.0.0.5:9402
   ```

   Each static target resolves to `http://<host>:<port>/metrics`.

3. Optional: To combine discovery and static targets, configure separate instances.
   The unnamed instance uses discovery, and the named instance scrapes the static
   targets:

   ```yaml theme={null}
   config:
     integrations:
       cert_manager: {}
       cert_manager/static:
         endpoints:
           - endpoint: 10.0.0.5:9402
   ```

### Validate

1. In the
   [Live Telemetry Analyzer](https://docs-xcor.paloaltonetworks.com/investigate/analyze/telemetry-analyzer),
   add the following label filters:

   * Set **Label** to `__name__` and **Value** to
     `cxdot.integration.target.health`.
   * Set **Label** to `cxdot.integration.name` and **Value** to `cert_manager`.

   Group the results by `cxdot.integration.target`, and confirm that the metric
   reports `1` for each target.

2. In
   [Metrics Explorer](https://docs-xcor.paloaltonetworks.com/investigate/querying/metrics/explorer),
   run the following query:

   ```text theme={null}
   max by ("certmanager.name", "k8s.namespace.name", "certmanager.condition") ({"certmanager.certificate.ready"})
   ```

   Confirm that the query returns a time series for each certificate condition.

## Disable the cert-manager integration

Deleting every `cert_manager` block restores the default unnamed instance. To remove
custom settings and stop collection, retain a disabled configuration:

```yaml theme={null}
config:
  integrations:
    cert_manager:
      enabled: false
```

## Configuration reference

Configure one cert-manager integration instance with the following settings. In Helm values,
place these settings under `config.integrations.cert_manager`. In a Collector configuration
file, place them under `cxdot.integrations.cert_manager`.

### Optional settings

* **`enabled`**
  Type: `boolean`. Optional. Default: `true`.
  Whether to enable this cert-manager integration instance. If true, the Collector runs the
  instance. If false, the Collector doesn't run it.

* **`endpoints`**
  Type: `array of object`. Optional. Default: `[]`.
  Static cert-manager targets. A nonempty list disables automatic discovery for this integration
  instance, and the Collector collects metrics from only the listed targets. Specify each target
  as `host:port`. The Collector requests `http://<host>:<port>/metrics`.

* **`endpoints[].endpoint`**
  Type: `string`. Required.
  cert-manager target in `host:port` format.

* **`collection_interval`**
  Type: `duration`. Optional. Default: `60s`.
  How often the Collector collects metrics from each cert-manager target.

* **`timeout`**
  Type: `duration`. Optional. Default: `60s`.
  Maximum time allowed to collect metrics from one cert-manager target. The value must not
  exceed `collection_interval`.


## Related topics

- [CXDOT Collector integrations](/ingest/xcor/integrations/collector.md)
- [Apache Spark](/ingest/xcor/integrations/collector/spark.md)
- [Differences between the Prometheus Operator and Chronosphere Collector](/ingest/metrics-traces/collector/mappings/prometheus/operator-collector.md)
- [ClickHouse](/ingest/xcor/integrations/collector/clickhouse.md)
- [MySQL](/ingest/xcor/integrations/collector/mysql.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.