OnCallReady

Commands

cmctl - manage and inspect cert-manager resources

cmctl COMMAND [NAME] [-n NAMESPACE]

Options you will use

status certificate NAME
the whole chain in one view: the Certificate's conditions, the Issuer, the Secret's certificate, and while issuing the CertificateRequest, Order and Challenges with their reasons
renew NAME | --all
mark a Certificate for re-issuance now (a new CertificateRequest revision)
inspect secret NAME
decode the certificate in a TLS Secret: names, validity, issuer
check api
is the cert-manager API (CRDs + webhook) ready? Run it right after installing
version
cmctl and the deployed cert-manager version
-n, --namespace NS
The namespace (default: the kubeconfig context's).
-A, --all-namespaces
Every namespace (renew --all).
--kubeconfig FILE
The kubeconfig to use.
--context NAME
The kubeconfig context to use.
-h, --help
Help for the command.

Examples

$ cmctl status certificate shop-tls -n shop

why is this certificate not Ready? The Challenge reason is at the bottom

$ cmctl renew shop-tls -n shop

Manually triggered issuance of Certificate shop/shop-tls

$ cmctl inspect secret shop-tls -n shop

Not After, Issued By: Pebble Intermediate CA ...

Gotchas

Taught in

Try cmctl in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.