Certificate Manager
Certificate Manager issues, renews and serves TLS certificates for Google's load balancers. The GCP Web App Blueprint uses it for the two public hostnames of every stage, with Google-managed certificates that are validated through DNS and renewed without anyone touching them.
What it does
A Google-managed certificate is issued and renewed by Google for the domains it lists. A DNS authorization proves control of a domain with a CNAME record that Google checks; it works before the hostname points at the load balancer, so issuance does not wait for traffic. A certificate map holds map entries that pair a hostname with certificates, and a load balancer's HTTPS proxy references the map rather than individual certificates.
How BuiltForProd uses it
Each stage has two certificates, one per load balancer, built the same way:
| Hostname | Unit | Map attached through |
|---|---|---|
blueprint-api.<stage>.company.com | api-gateway | the Gateway annotation networking.gke.io/certmap |
blueprint-app.<stage>.company.com | frontend-service | the certificate_map of the SPA's target HTTPS proxy |
For each hostname the unit creates a DNS authorization (<prefix>-api-dnsauth, <prefix>-frontend-dnsauth), writes its CNAME record into the stage's public zone in acme-core-dns, then the certificate (-api-cert, -frontend-cert), the map (-api-certmap, -frontend-certmap) and the map entry for the hostname. The record is written through the google.dns provider alias as the stage deployer, which holds roles/dns.admin on that stage zone only; see Cloud DNS.
A certificate turns ACTIVE once its hostname resolves to the load balancer: for the SPA, the unit writes the A record itself; for the API, external-dns writes it from the chart's HTTPRoute after the Gateway exists. The API's map name reaches the chart through the Parameter Manager parameter api--certificate-map; see GKE Gateway.
Both proxies also carry an SSL policy with the MODERN profile and TLS 1.2 minimum, set on the load balancers.
Internal hostnames are not here. The ArgoCD host under internal.company.com is served by the internal certificate authority that cert-manager runs inside the cluster; no ACME issuer and no public certificate is involved.
Terms you will see
| Term | Meaning |
|---|---|
| DNS authorization | The CNAME challenge that proves control of a hostname to Google. |
| Certificate map | The set of hostname-to-certificate entries a proxy serves. |
| Map entry | One hostname paired with its certificates. |
ACTIVE | The certificate state once it is issued and served. |
api--certificate-map | The parameter that hands the API's map name to the chart's Gateway. |
Where to read more
- GCP Web App Blueprint overview for the public hostnames.
- Cloud DNS for the stage zones and who writes into them.
- cert-manager for the internal certificates.