We are excited to announce the general availability of a new capability for edge Kubernetes workloads connected with Azure Arc, Certificate Management. Certificate Management enables Arc-enabled Kubernetes customers to install a single Microsoft-supported extension to automate TLS certificate and trust bundle management across their edge fleets. The extension is supported for production workloads under standard Microsoft support agreements.
What it is
The Certificate Management extension packages two CNCF-graduated projects, cert-manager and trust-manager, into one Microsoft-managed Arc extension, installed once per cluster. After installation, customers can:
- Issue, renew, and rotate certificates automatically, with no manual steps.
- Distribute trusted CA certificates to the namespaces that need them, without copying ConfigMaps by hand.
- Use the built-in self-signed CA for development and testing, or connect an enterprise CA issuer for production.
- Rely on Microsoft enterprise support, security patches, and ongoing maintenance for the extension.
Why it matters
Certificate management at the edge gets operationally complex quickly. Certificates expire, clusters may run different tooling, and teams must track renewals, CVEs, version compatibility, and support boundaries. Running upstream open-source components directly leaves that operational burden with the customer.
The Certificate Management extension takes this undifferentiated work off of the customer’s plate. It enables them to offload lifecycle management for the TLS certificates that secure communications between Kubernetes workloads inside and outside the cluster. Instead of managing and maintaining upstream open-source cert-manager and trust-manager projects themselves for critical aspects of Kubernetes workload security, customers can use a secure-by-default, a Microsoft-supported experience.
Feedback from customers in manufacturing, retail, and other distributed enterprise environments shaped the GA release. The goal is to strengthen security posture, reduce operational risk, and simplify certificate management across large Arc-enabled edge fleets.
What’s included in the GA release
Production support: The extension is supported for production deployments under standard Microsoft support agreements. If certificate issuance fails in production, Microsoft customers can open a support ticket and engage Microsoft Customer Service and Support.
Works through disconnection: Certificates and trust bundles continue to function when a cluster temporarily loses connectivity to Azure, supporting edge sites that may operate offline for extended periods.
Broad regional and distribution coverage: The extension is available in most Azure regions and validated on AKS Edge Essentials, AKS on Azure Local, Red Hat OpenShift, SUSE Rancher RKE2, VMware Tanzu, and K3s. See the documentation for the full validated list and regional availability.
ARM64 platform support: The Certificate Management extension now supports ARM64 architectures, enabling deployment on ARM64-based edge infrastructure alongside existing supported architectures.
Get started
The extension is now generally available. If you already deployed the public preview, you can carry those deployments forward by updating to the latest version and without making any changes to your configuration.
Get started with the Certificate Management extension by following the documentation and quickstart.