Skip to main content

Certificate Manager

Certificate Manager issues, renews and serves TLS certificates for Google's load balancers. The GCP Web App Blueprint uses it for the two public hostnames of every stage, with Google-managed certificates that are validated through DNS and renewed without anyone touching them.

What it does​

A Google-managed certificate is issued and renewed by Google for the domains it lists. A DNS authorization proves control of a domain with a CNAME record that Google checks; it works before the hostname points at the load balancer, so issuance does not wait for traffic. A certificate map holds map entries that pair a hostname with certificates, and a load balancer's HTTPS proxy references the map rather than individual certificates.

How BuiltForProd uses it​

Each stage has two certificates, one per load balancer, built the same way:

HostnameUnitMap attached through
blueprint-api.<stage>.company.comapi-gatewaythe Gateway annotation networking.gke.io/certmap
blueprint-app.<stage>.company.comfrontend-servicethe certificate_map of the SPA's target HTTPS proxy

For each hostname the unit creates a DNS authorization (<prefix>-api-dnsauth, <prefix>-frontend-dnsauth), writes its CNAME record into the stage's public zone in acme-core-dns, then the certificate (-api-cert, -frontend-cert), the map (-api-certmap, -frontend-certmap) and the map entry for the hostname. The record is written through the google.dns provider alias as the stage deployer, which holds roles/dns.admin on that stage zone only; see Cloud DNS.

A certificate turns ACTIVE once its hostname resolves to the load balancer: for the SPA, the unit writes the A record itself; for the API, external-dns writes it from the chart's HTTPRoute after the Gateway exists. The API's map name reaches the chart through the Parameter Manager parameter api--certificate-map; see GKE Gateway.

Both proxies also carry an SSL policy with the MODERN profile and TLS 1.2 minimum, set on the load balancers.

Internal hostnames are not here. The ArgoCD host under internal.company.com is served by the internal certificate authority that cert-manager runs inside the cluster; no ACME issuer and no public certificate is involved.

Terms you will see​

TermMeaning
DNS authorizationThe CNAME challenge that proves control of a hostname to Google.
Certificate mapThe set of hostname-to-certificate entries a proxy serves.
Map entryOne hostname paired with its certificates.
ACTIVEThe certificate state once it is issued and served.
api--certificate-mapThe parameter that hands the API's map name to the chart's Gateway.

Where to read more​