Integrations
Kubernetes TLS Secret Automation
First-Party Platform Target
SSLNexus publishes managed certificates directly to the Kubernetes HTTPS API as standard kubernetes.io/tls Secrets. No in-cluster SSLNexus agent is required.
Configuration
- Kubernetes API endpoint.
- Namespace and TLS Secret name.
- A dedicated service-account bearer token scoped to read/update the selected Secret wherever possible.
Workflow
- Read the current Secret to determine create/update semantics.
- Create or replace the Secret using
tls.crtandtls.key. - Read the Secret back and verify the standard TLS Secret type.
- Record the namespace/Secret binding for future renewal and impact analysis.
Ingress/Gateway/controller reload behaviour remains the responsibility of the consuming Kubernetes platform; SSLNexus manages the Secret lifecycle and verifies the API object.

