Integrations
Certificate Destinations
Vault · AWS · Azure
Certificate destinations publish a successfully managed certificate to an approved secret store in addition to normal application deployment. They are deliberately separate from deployment adapters and CA connectors.
Supported Destinations
- HashiCorp Vault KV v2 — publish managed certificate material to a configured KV path.
- AWS Secrets Manager — publish to the selected AWS region and secret name.
- Azure Key Vault — publish to a configured Key Vault using the saved application identity.
Lifecycle
Bind a certificate to one or more destinations. The current certificate is published immediately and every future successful issuance/renewal republishes the new material. Normal deployment targets remain independent.
Vault KV is a certificate destination. Vault PKI is a separate certificate-authority connector and is configured on the deployment target's CA profile.

