Certificate Manager
When you enable the Certificate Manager cluster add-on, you can pass the following key/value pairs as arguments.
| Key (API and CLI) | Key's Display Name (Console) | Description | Required/Optional | Default Value | Example Value |
|---|---|---|---|---|---|
affinity |
affinity |
A group of affinity scheduling rules. JSON format in plain text or Base64 encoded. Not used by:
Possible equivalents:
|
Optional | null | null |
nodeSelectors |
node selectors |
You can use node selectors and node labels to control the worker nodes on which add-on pods run. For a pod to run on a node, the pod's node selector must have the same key/value as the node's label. Set JSON format in plain text or Base64 encoded. Not used by:
Possible equivalents:
|
Optional | null | {"foo":"bar", "foo2": "bar2"}The pod will only run on nodes that have the |
numOfReplicas |
numOfReplicas | The number of replicas of the add-on deployment. Not used by:
Possible equivalents:
|
Required | 1Creates one replica of the add-on deployment per cluster. |
2Creates two replicas of the add-on deployment per cluster. |
rollingUpdate |
rollingUpdate |
Controls the desired behavior of rolling update by maxSurge and maxUnavailable. JSON format in plain text or Base64 encoded. Not used by:
Possible equivalents:
|
Optional | null | null |
tolerations |
tolerations |
You can use taints and tolerations to control the worker nodes on which add-on pods run. For a pod to run on a node that has a taint, the pod must have a corresponding toleration. Set JSON format in plain text or Base64 encoded. Possible equivalents:
|
Optional | null | [{"key":"tolerationKeyFoo", "value":"tolerationValBar", "effect":"noSchedule", "operator":"exists"}]Only pods that have this toleration can run on worker nodes that have the |
topologySpreadConstraints |
topologySpreadConstraints |
How to spread matching pods among the given topology. JSON format in plain text or Base64 encoded. Not used by:
|
Optional | null | null |
| Key (API and CLI) | Key's Display Name (Console) | Description | Required/Optional | Default Value | Example Value |
|---|---|---|---|---|---|
cert-manager-cainjector.ContainerResources
|
cert-manager-cainjector container resources |
You can specify the resource quantities that the add-on containers request, and set resource usage limits that the add-on containers cannot exceed. JSON format in plain text or Base64 encoded. |
Optional | null |
{"limits": {"cpu": "500m", "memory": "200Mi" }, "requests": {"cpu": "100m", "memory": "100Mi"}}
Create add-on containers that request 100 milllicores of CPU, and 100 mebibytes of memory. Limit add-on containers to 500 milllicores of CPU, and 200 mebibytes of memory. |
cert-manager-controller.ContainerResources
|
cert-manager-controller container resources |
You can specify the resource quantities that the add-on containers request, and set resource usage limits that the add-on containers cannot exceed. JSON format in plain text or Base64 encoded. |
Optional | null |
{"limits": {"cpu": "500m", "memory": "200Mi" }, "requests": {"cpu": "100m", "memory": "100Mi"}}
Create add-on containers that request 100 milllicores of CPU, and 100 mebibytes of memory. Limit add-on containers to 500 milllicores of CPU, and 200 mebibytes of memory. |
cert-manager-webhook.ContainerResources
|
cert-manager-webhook container resources |
You can specify the resource quantities that the add-on containers request, and set resource usage limits that the add-on containers cannot exceed. JSON format in plain text or Base64 encoded. |
Optional | null |
{"limits": {"cpu": "500m", "memory": "200Mi" }, "requests": {"cpu": "100m", "memory": "100Mi"}}
Create add-on containers that request 100 milllicores of CPU, and 100 mebibytes of memory. Limit add-on containers to 500 milllicores of CPU, and 200 mebibytes of memory. |
The following table describes considerations for configuring this cluster add-on in large clusters.
| Argument Name | Roles wrt number of Nodes | Description | As cluster size increases | Risks | Recommendation |
|---|---|---|---|---|---|
cert-manager-cainjector.ContainerResources
|
Y |
Defines CPU and memory resources for the CA Injector. |
The CA Injector adds CA data to webhooks, custom resource definitions, and API services. As the cluster size increases:
The workload grows moderately and is generally lower than the workload of the Certificate Manager controller. |
If the resources are undersized:
|
Increase resources moderately as the cluster size increases. The CA Injector typically requires less aggressive resource scaling than the Certificate Manager controller. |
numOfReplicas
|
N |
Controls the number of replicas for Certificate Manager components. |
Additional replicas improve availability and fault tolerance. The webhook can scale horizontally to handle a higher volume of admission requests. |
|
|
affinity
/
nodeSelectors
/
tolerations
|
N |
Control the placement of Certificate Manager components. |
Certificate Manager is a control-plane-critical component and can be affected by node churn and resource contention. |
If these arguments are not configured appropriately:
|
|
rollingUpdate
|
N |
Controls the deployment update strategy. |
During an upgrade:
|
|
|
topologySpreadConstraints
|
N |
Controls how pods are distributed across nodes and availability domains. |
|
If topology spread constraints are not configured:
|
Distribute replicas across different nodes and availability domains. |
cert-manager-controller.ContainerResources
|
Y |
Defines CPU and memory resources for the Certificate Manager controller pod. |
As the cluster size increases, the number of the following resources can increase:
The controller experiences:
|
If the resources are undersized:
|
This is the most important Certificate Manager resource-scaling argument. |
cert-manager-webhook.ContainerResources
|
Y |
Defines CPU and memory resources for the Certificate Manager webhook. |
The webhook validates and modifies Certificate Manager resources. As the cluster size increases:
|
If the resources are undersized:
|
|