Get started with Chkk for free today! No credit card required
Learn more
Learn more
Back to the blog
Spotlight
June 30, 2025

Spotlight: Seamless cert-manager Upgrades with Chkk

Written by
Chkk Team
X logoLinkedin logo
Start for free
Estimated Reading time
5 min

cert-manager is a widely adopted Kubernetes add-on that automates the issuance and renewal of TLS certificates for cluster workloads. By integrating with multiple certificate authorities (including ACME providers like Let’s Encrypt), cert-manager streamlines the process of requesting and validating certificates, significantly reducing manual effort. It continuously monitors certificate expiration and renews them ahead of time, ensuring secure communication for applications at scale.

However, for teams that rely on cert-manager in their clusters, upgrading this add-on can present significant operational risks—such as changes to CRDs, renamed API fields, or new webhook requirements that come with newer Kubernetes versions. Without careful planning, such changes could lead to failed certificate issuances or unexpected downtime after an upgrade. In this post, we’ll show you how Chkk’s Operational Safety Platform offers an end-to-end solution for managing cert-manager upgrades. 

Chkk’s Coverage for cert-manager

Curated Release Notes

Chkk tracks cert-manager release notes to highlight new features, breaking changes, or CRD updates relevant to your environment. It alerts you to shifts—like renamed or removed API versions—so you can adapt configurations before upgrading. Each curated summary points out potential operational impacts, saving your team from going through long upstream changelogs. This way, you stay focused on what matters and avoid unexpected issues during upgrades.

Preflight & Postflight Checks

Before any upgrade, Chkk’s preflight checks validate that your cluster meets cert-manager’s requirements: for example, verifying the Kubernetes version compatibility, ensuring CRDs and the cert-manager webhook are ready, and flagging any deprecated APIs in use that might be removed in the new release. 

After the upgrade, postflight checks confirm everything is functioning correctly—healthy controller pods, a responsive webhook, and successful certificate issuance/renewals. This two-step validation ensures certificate management continues uninterrupted, quickly catching any errors so teams can address issues early.

Version Recommendations

Chkk continuously monitors cert-manager’s release timeline and support lifecycle, flagging EOL risks or critical security patches for the version you’re running. It factors in Kubernetes version compatibility to recommend the safest, most stable release to upgrade to. You’ll receive alerts well before your current version becomes unsafe or unsupported, along with suggestions for the best minor version to minimize breaking changes. Following these recommendations helps you stay ahead of critical updates and avoid running outdated, risky versions of cert-manager.

Upgrade Templates

Whether you prefer an in-place update or a blue-green deployment, Chkk provides step-by-step Upgrade Templates tailored to cert-manager:

  • In-place Upgrades sequentially update the cert-manager CRDs and controller within your cluster, preserving ongoing certificate services during the process.
  • Blue-Green Deployments launch a parallel cert-manager instance on the new version and cut over to it once it’s verified, minimizing any potential downtime or disruption.

Both strategies come with detailed checks and defined rollback points, letting you handle both minor version bumps and major changes with peace of mind.

Preverification

For major or complex upgrades—especially those involving significant cert-manager changes or new ACME configurations—Chkk’s preverification feature tests the process in a controlled environment before you apply it in production. It spins up a test environment with your Issuer and Certificate custom resources, runs the new cert-manager controller, and checks for issues on the target version. This “dry-run” upgrade lets you identify and fix problems ahead of time. By validating your exact setup against the new version, preverification greatly reduces downtime risk and gives you confidence in a smooth upgrade.

Supported Packages

Whether your team installs cert-manager via the official Helm chart, operators, or raw YAML manifests, Chkk seamlessly integrates into your deployment workflow. It adapts to custom installation scenarios, supporting private container registries, custom-built cert-manager images, or vendor-specific cert-manager forks, ensuring that the Upgrade Plan aligns with your existing management methods. Regardless of deployment style, Chkk’s comprehensive coverage guarantees consistency and repeatability in the upgrade process across all your environments.

Chkk’s Core Benefits

Chkk Operational Safety Platform simplifies upgrades, reduces risk, and keeps your Kubernetes infrastructure operational. Here’s how that applies to cert-manager upgrades:

  • Speed Up and De-Risk Upgrades: Manually upgrading cert-manager is time-consuming. Chkk accelerates the process and makes it safer by generating a detailed Upgrade Plan for each cluster. This plan spans all components—control plane, node versions, add-ons, and dependencies—and flags required changes, including recommended add-on versions or deprecated APIs. Instead of piecing together requirements from various release notes, teams receive a clear and actionable upgrade path. Chkk’s automation can cut upgrade preparation time by 3-5x, reducing weeks of planning to just days.
  • Eliminate Redundant Effort: Many organizations squander countless hours on repetitive upgrade planning and research. By unifying upgrade workflows across teams, Chkk prevents duplication of effort and ensures that insights and processes don’t need to be reinvented with every release. This consolidation of efforts can save thousands of hours.
  • Delegate, Parallelize, and Standardize Workflows: Chkk makes it easy to break out upgrade tasks among team members, all while maintaining standardized workflows that reduce confusion and boost efficiency. Engineers spend less time context-switching, and institutional knowledge is retained and shared effectively. During staff turnover or organizational changes, having a historical record of upgrade best practices prevents delays.
  • Enhance Operational Safety: Kubernetes upgrades introduce inherent risk, but Chkk helps you detect and fix potential problems before they cause disruptions. With automated risk detection, your team can prevent hundreds of potential breakages annually—for every hundred clusters—saving significant break-fix effort. By focusing on proactive measures, you can innovate rather than constantly firefighting.
Chkk's core benefits: speed up and de-risk upgrades, proactive risk detection, eliminate redundant effort, delegate and standardize workflows.

Simplify Upgrades for cert-manager and 100s of Other Kubernetes Add-ons

Try Chkk Upgrade Copilot to experience how these extended capabilities can simplify your upgrade processes for cert-manager and 100s of other Kubernetes Add-ons, Application Services, and Open Source Projects. We look forward to helping you achieve seamless, secure, and efficient operations. 

Click the button below to book a demo and learn more.

cert-manager is a widely adopted Kubernetes add-on that automates the issuance and renewal of TLS certificates for cluster workloads. By integrating with multiple certificate authorities (including ACME providers like Let’s Encrypt), cert-manager streamlines the process of requesting and validating certificates, significantly reducing manual effort. It continuously monitors certificate expiration and renews them ahead of time, ensuring secure communication for applications at scale.

However, for teams that rely on cert-manager in their clusters, upgrading this add-on can present significant operational risks—such as changes to CRDs, renamed API fields, or new webhook requirements that come with newer Kubernetes versions. Without careful planning, such changes could lead to failed certificate issuances or unexpected downtime after an upgrade. In this post, we’ll show you how Chkk’s Operational Safety Platform offers an end-to-end solution for managing cert-manager upgrades. 

Chkk’s Coverage for cert-manager

Curated Release Notes

Chkk tracks cert-manager release notes to highlight new features, breaking changes, or CRD updates relevant to your environment. It alerts you to shifts—like renamed or removed API versions—so you can adapt configurations before upgrading. Each curated summary points out potential operational impacts, saving your team from going through long upstream changelogs. This way, you stay focused on what matters and avoid unexpected issues during upgrades.

Preflight & Postflight Checks

Before any upgrade, Chkk’s preflight checks validate that your cluster meets cert-manager’s requirements: for example, verifying the Kubernetes version compatibility, ensuring CRDs and the cert-manager webhook are ready, and flagging any deprecated APIs in use that might be removed in the new release. 

After the upgrade, postflight checks confirm everything is functioning correctly—healthy controller pods, a responsive webhook, and successful certificate issuance/renewals. This two-step validation ensures certificate management continues uninterrupted, quickly catching any errors so teams can address issues early.

Version Recommendations

Chkk continuously monitors cert-manager’s release timeline and support lifecycle, flagging EOL risks or critical security patches for the version you’re running. It factors in Kubernetes version compatibility to recommend the safest, most stable release to upgrade to. You’ll receive alerts well before your current version becomes unsafe or unsupported, along with suggestions for the best minor version to minimize breaking changes. Following these recommendations helps you stay ahead of critical updates and avoid running outdated, risky versions of cert-manager.

Upgrade Templates

Whether you prefer an in-place update or a blue-green deployment, Chkk provides step-by-step Upgrade Templates tailored to cert-manager:

  • In-place Upgrades sequentially update the cert-manager CRDs and controller within your cluster, preserving ongoing certificate services during the process.
  • Blue-Green Deployments launch a parallel cert-manager instance on the new version and cut over to it once it’s verified, minimizing any potential downtime or disruption.

Both strategies come with detailed checks and defined rollback points, letting you handle both minor version bumps and major changes with peace of mind.

Preverification

For major or complex upgrades—especially those involving significant cert-manager changes or new ACME configurations—Chkk’s preverification feature tests the process in a controlled environment before you apply it in production. It spins up a test environment with your Issuer and Certificate custom resources, runs the new cert-manager controller, and checks for issues on the target version. This “dry-run” upgrade lets you identify and fix problems ahead of time. By validating your exact setup against the new version, preverification greatly reduces downtime risk and gives you confidence in a smooth upgrade.

Supported Packages

Whether your team installs cert-manager via the official Helm chart, operators, or raw YAML manifests, Chkk seamlessly integrates into your deployment workflow. It adapts to custom installation scenarios, supporting private container registries, custom-built cert-manager images, or vendor-specific cert-manager forks, ensuring that the Upgrade Plan aligns with your existing management methods. Regardless of deployment style, Chkk’s comprehensive coverage guarantees consistency and repeatability in the upgrade process across all your environments.

Chkk’s Core Benefits

Chkk Operational Safety Platform simplifies upgrades, reduces risk, and keeps your Kubernetes infrastructure operational. Here’s how that applies to cert-manager upgrades:

  • Speed Up and De-Risk Upgrades: Manually upgrading cert-manager is time-consuming. Chkk accelerates the process and makes it safer by generating a detailed Upgrade Plan for each cluster. This plan spans all components—control plane, node versions, add-ons, and dependencies—and flags required changes, including recommended add-on versions or deprecated APIs. Instead of piecing together requirements from various release notes, teams receive a clear and actionable upgrade path. Chkk’s automation can cut upgrade preparation time by 3-5x, reducing weeks of planning to just days.
  • Eliminate Redundant Effort: Many organizations squander countless hours on repetitive upgrade planning and research. By unifying upgrade workflows across teams, Chkk prevents duplication of effort and ensures that insights and processes don’t need to be reinvented with every release. This consolidation of efforts can save thousands of hours.
  • Delegate, Parallelize, and Standardize Workflows: Chkk makes it easy to break out upgrade tasks among team members, all while maintaining standardized workflows that reduce confusion and boost efficiency. Engineers spend less time context-switching, and institutional knowledge is retained and shared effectively. During staff turnover or organizational changes, having a historical record of upgrade best practices prevents delays.
  • Enhance Operational Safety: Kubernetes upgrades introduce inherent risk, but Chkk helps you detect and fix potential problems before they cause disruptions. With automated risk detection, your team can prevent hundreds of potential breakages annually—for every hundred clusters—saving significant break-fix effort. By focusing on proactive measures, you can innovate rather than constantly firefighting.
Chkk's core benefits: speed up and de-risk upgrades, proactive risk detection, eliminate redundant effort, delegate and standardize workflows.

Simplify Upgrades for cert-manager and 100s of Other Kubernetes Add-ons

Try Chkk Upgrade Copilot to experience how these extended capabilities can simplify your upgrade processes for cert-manager and 100s of other Kubernetes Add-ons, Application Services, and Open Source Projects. We look forward to helping you achieve seamless, secure, and efficient operations. 

Click the button below to book a demo and learn more.

Tags
Add-ons
cert-manager

Continue reading

Spotlight

Spotlight: Simplifying Contour Upgrades with Chkk

by
Chkk Team
Read more
Hidden Toil

5 Reasons Why Delaying Open Source Software Upgrades Is a Bad Idea

by
Awais Nemat
Read more
Spotlight

Spotlight: Seamless cert-manager Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: Argo Rollouts Upgrades with Chkk

by
Chkk Team
Read more
Upgrade Advisory

Upgrade Advisory: Pods Stuck in Pending During Kubelet v1.30 → v1.31 Upgrade

by
Chkk Team
Read more
Spotlight

Spotlight: Simplifying Self-Managed Apache Kafka Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: Seamless Calico Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: NGINX Ingress Controller Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: KEDA Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: Streamlining Prometheus Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: RabbitMQ Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: Seamless Kyverno Upgrades with Chkk

by
Chkk Team
Read more
News

Google Container Registry Deprecation 2025: How to Migrate to Artifact Registry

by
Chkk Team
Read more
Spotlight

Spotlight: HashiCorp Vault Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: Streamlining Crossplane Upgrades with Chkk

by
Chkk Team
Read more
Spotlight

Spotlight: Seamless External DNS Upgrades with Chkk

by
Chkk Team
Read more
Case Study

How Dexcom Derisked GKE Upgrades and Sped Them Up by 5x using Chkk

by
Chkk Team
Read more
Case Study

Assuring Compliance and Availability for Yoti’s On-Prem Platform with Chkk

by
Chkk Team
Read more
Case Study

How a Fortune 500 Enterprise Avoided $500K in EKS Extended Support Fees, Achieved 80% Reduction in Prep Time, and Boosted Upgrade Productivity by 200%

by
Chkk Team
Read more
Case Study

How a Fortune 1000 Enterprise Standardized Multi-Cloud (EKS & GKE) Upgrades for 30+ Add-Ons, Avoided 6x Costs, and Achieved an 80% Reduction in Prep Time

by
Chkk Team
Read more
Spotlight

Spotlight: Upgrading Self-Managed Redis

by
Chkk Team
Read more
Spotlight

Spotlight: Simplifying Self-Managed Elasticsearch Upgrades with Chkk

by
Chkk Team
Read more
News

GKE & EKS Extended Support: Are 6x Fees for Supporting Older Kubernetes Versions Justified?

by
Ali Khayam
Read more
Spotlight

Spotlight: Seamless Karpenter Upgrades with Chkk

by
Chkk Team
Read more
Operational Safety

Forced EKS & GKE Upgrades: How to Manage Business Continuity Risks

by
Fawad Khaliq
Read more
Spotlight

Spotlight: How Chkk Streamlines & Safeguards Cilium Upgrades

by
Chkk Team
Read more
Technology

Kubernetes Admission Controllers and Webhooks Deep Dive

by
Chkk Team
Read more
Spotlight

Chkk Spotlight: Istio

by
Chkk Team
Read more
Technology

Pod Disruption Budgets: Pitfalls, Evictions & Kubernetes Upgrades

by
Chkk Team
Read more
Technology

cgroup v1 to v2 Migration in Kubernetes

by
Chkk Team
Read more
Operational Safety

OpenAI’s Outage: The Complexity and Fragility of Modern AI Infrastructure on Kubernetes

by
Fawad Khaliq
Read more
News

EKS launches Auto Mode… How can you adopt it?

by
Ali Khayam
Read more
Change Safety

CrowdStrike outage was the symptom; missing Operational Safety was the cause

by
Fawad Khaliq
Read more
News

GKE Follows EKS & AKS, Launches Extended Support with a 500% Surcharge for Delayed Upgrade

by
Ali Khayam
Read more
News

AKS Long Term Support and EKS Extended Support: Similarities & Differences

by
Ali Khayam
Read more
News

Amazon launches EKS extended support… How does it impact you?

by
Ali Khayam
Read more
Platform Engineering

Platform teams need a delightfully different approach, not one that sucks less

by
Fawad Khaliq
Read more
Technology

Kubernetes Enters Its Second Decade: Insights from KubeCon Chicago

by
Fawad Khaliq
Read more
Company

Launching Chkk Operational Safety Platform

by
Awais Nemat
Read more
Technology

What Makes Kubernetes Upgrades So Challenging?

by
Fawad Khaliq
Read more
Company

4 Lessons from our SOC2 Journey

by
Fawad Khaliq
Read more
Technology

Collective Learning: The Power of Not Repeating Others’ Mistakes

by
Ali Khayam
Read more
Technology

From Fighting Fires to Availability Assurance

by
Fawad Khaliq
Read more
Company

Welcome to Chkk

by
Awais Nemat
Read more