cmctl - manage and inspect cert-manager resources
cmctl COMMAND [NAME] [-n NAMESPACE]
Options you will use
status certificate NAME- the whole chain in one view: the Certificate's conditions, the Issuer, the Secret's certificate, and while issuing the CertificateRequest, Order and Challenges with their reasons
renew NAME | --all- mark a Certificate for re-issuance now (a new CertificateRequest revision)
inspect secret NAME- decode the certificate in a TLS Secret: names, validity, issuer
check api- is the cert-manager API (CRDs + webhook) ready? Run it right after installing
version- cmctl and the deployed cert-manager version
-n, --namespace NS- The namespace (default: the kubeconfig context's).
-A, --all-namespaces- Every namespace (renew --all).
--kubeconfig FILE- The kubeconfig to use.
--context NAME- The kubeconfig context to use.
-h, --help- Help for the command.
Examples
$ cmctl status certificate shop-tls -n shopwhy is this certificate not Ready? The Challenge reason is at the bottom
$ cmctl renew shop-tls -n shopManually triggered issuance of Certificate shop/shop-tls
$ cmctl inspect secret shop-tls -n shopNot After, Issued By: Pebble Intermediate CA ...
Gotchas
- cmctl is a separate binary (v2.6, github.com/cert-manager/cmctl); it used to be kubectl cert-manager. The same verbs work as the kubectl plugin.
Taught in
Try cmctl in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.