Secure

SSL management: no more outages caused by an expired certificate

Discover every certificate in the estate, including the ones nobody documented, renew them automatically, and get warned in weeks rather than hours.

Short answer

What is SSL Management?

DevOpsArk SSL management is the module that discovers, monitors, renews and reports on TLS certificates across Kubernetes ingresses, load balancers, servers and public endpoints.

Why it matters

What SSL Management is for

The conditions this module removes. If none of these are familiar, you probably do not need it yet.

  • A certificate nobody knew about expires and takes a service down on a Saturday.
  • Certificates are issued by three different processes and tracked in none of them.
  • Renewal reminders go to a mailbox belonging to someone who left.
  • The internal certificate authority issues certificates that no inventory records.
  • Weak protocol versions and cipher suites persist because nobody audits endpoints.
How it works

SSL management discovers certificates from three directions at once: Kubernetes ingress and Secret resources, cloud load balancers and certificate services, and direct probing of the endpoints in your inventory, which is how it finds the certificates that were never recorded anywhere. Each certificate is tracked with its issuer, subject alternative names, expiry, the endpoints presenting it and the team that owns the service behind it. Renewal is automated where an ACME issuer such as Let us Encrypt or an internal certificate authority can be used, and coordinated with the load balancer or ingress so the new certificate is in place before the old one lapses. Where renewal must remain manual, escalating notifications begin weeks ahead and go to the owning team rather than to a mailbox. The same endpoint probing reports protocol versions, cipher suites and chain problems, so certificate hygiene is measured rather than assumed.

Capabilities

What SSL Management does

The 6 capabilities that make up SSL Management.

Certificate discovery

From Kubernetes resources, cloud load balancers and certificate services, and by probing endpoints directly to find undocumented certificates.

Automated renewal

ACME and internal certificate authority issuance, coordinated with ingresses and load balancers so the new certificate is installed before expiry.

Escalating expiry alerts

Notifications begin weeks ahead and escalate, routed to the team that owns the service rather than a shared mailbox.

Protocol and cipher audit

Reports weak TLS versions, deprecated cipher suites, incomplete chains and hostname mismatches per endpoint.

Wildcard and SAN tracking

Understands which services depend on a shared wildcard or multi-domain certificate, so its renewal blast radius is known.

Certificate inventory

One list of every certificate with issuer, expiry, owner and the endpoints presenting it.

Architecture

How SSL Management fits together

Discovery
Kubernetes ingress and secretsCloud load balancersEndpoint probingInternal CA
SSL management
Certificate inventoryRenewal engineExpiry escalationTLS audit
Issuers
ACMEInternal CACloud certificate services
Consumers
Ingress controllersLoad balancersServers
SSL Management architecture within the DevOpsArk control plane.

Outcomes

  • Expiry-driven outages stop, because discovery covers the certificates nobody documented.
  • Renewal happens automatically wherever an issuer is available.
  • Warnings reach the team that can act, weeks ahead.
  • Weak TLS configuration is measured continuously instead of at audit time.
  • The blast radius of a shared wildcard certificate is known before it is renewed.
How to use it

Using SSL Management, step by step

The path from connecting a source to getting value, in the order it happens.

  1. 1
    Discover

    Certificates are found from Kubernetes, cloud services and direct endpoint probing.

  2. 2
    Attribute

    Each certificate is linked to its endpoints and the owning team.

  3. 3
    Automate renewal

    ACME or internal CA issuance is configured where possible.

  4. 4
    Install and verify

    The new certificate is installed and the endpoint is probed to confirm.

  5. 5
    Audit continuously

    Protocol versions, cipher suites and chains are checked on a schedule.

Use cases

Where teams apply SSL Management

SRE

Eliminate expiry outages

Discover every certificate, automate renewal where possible and escalate the rest early.

Security

Audit TLS configuration

Report weak protocol versions and cipher suites across all public and internal endpoints.

Platform engineering

Standardise issuance

Route all issuance through one automated path instead of three ad-hoc processes.

Compliance

Evidence certificate control

Produce the certificate inventory with issuer, expiry and owner on request.

Supported technologies

What SSL Management works with

Named integrations link to their own page. The rest are supported runtimes and formats.

kubernetesawsazuregcpLet's Encryptcert-managerACMENGINXIstio
Do not see your stack? DevOpsArk works over standard interfaces: the Kubernetes API, OCI images, OpenTelemetry and cloud provider APIs, so most environments are supported without a bespoke connector. Ask us about yours.
FAQ

SSL Management: frequently asked questions

The 7 questions teams ask most often before adopting SSL Management.

See SSL Management against your own environment

A 30-minute walkthrough with a platform engineer, not a sales deck. Bring a cluster and a problem.