---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Certificate generation through Kubernetes cert-manager

# Certificate generation through Kubernetes cert-manager {#ariaid-title1}

* Release version: Yokohama
* 
* Updated October 29, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Certificate generation through Kubernetes cert-manager

This guide explains how ServiceNow customers can request and manage certificates within a Kubernetes cluster using the Kubernetes cert-manager integrated with the ServiceNow External Issuer (sn-external-issuer).
Certificates and their related sensitive information are securely stored as Kubernetes secrets, enabling streamlined certificate lifecycle management directly through ServiceNow's platform.
Show full answer Show less  

## Deployment Requirements

* Deploy cert-manager in your Kubernetes environment.
* Update the **manager.yaml** file with details such as Instance URL, Certificate Owner Group, Certificate Owner, Environment, and Renewal Tracking.
* Deploy the ServiceNow External Issuer (sn-external-issuer) in Kubernetes.
* Create a Kubernetes secret `clusterissuer-servicenow-credentials` containing the ServiceNow instance username and password. Ensure this user has the necessary roles to request certificates.
* The External Issuer supports amd64 architecture and Kubernetes version 1.33.3 or later.

## ServiceNow External Issuer Functionality

The ServiceNow External Issuer extends cert-manager's capabilities by integrating with ServiceNow's APIs to issue certificates. Key behaviors include:

* Storing Certificate Request UID and Certificate Task Sys Id in a local JSON cache and ServiceNow instance tables.
* Polling the ServiceNow instance to track certificate task status.
* When the task completes, downloading the issued certificate and updating the certificate resource and Kubernetes secret accordingly.
* Synchronizing between cert-manager and ServiceNow instance to ensure accurate certificate request tracking and issuance.

## Deploying the ServiceNow External Issuer in Kubernetes

* Obtain the Helm Chart or YAML package from the ServiceNow instance download page.
* Customize the `manager.yaml` or `values.yaml` files with your instance information and certificate owner details.
* Create the Kubernetes secret `clusterissuer-servicenow-credentials` with instance credentials using `kubectl create secret generic`.
* Run the necessary `kubectl` commands to create the namespace, apply Custom Resource Definitions (CRDs), RBAC, issuers, and deploy the manager component.
* Verify that the ServiceNow External Issuer is running successfully.

## Requesting a New Certificate

After deployment, submit a certificate request by applying a certificate resource YAML file that references the ServiceNow External Issuer. This includes:

* Defining the `ClusterIssuer` with `issuerRef` pointing to `clusterissuer-servicenow`.
* Specifying certificate details such as `commonName`, `dnsNames`, and the secret name where the certificate will be stored.
* Applying the certificate resource using `kubectl apply -f certificateclusterissuer.yaml`.

This process initiates the certificate generation workflow through ServiceNow, with cert-manager handling certificate issuance, storage, and renewal transparently.  
Request a certificate through Kubernetes cert-manager using the ServiceNow External Issuer (sn-external-issuer) and save the certificate and its related information securely within the Kubernetes cluster as a secret. In Kubernetes, a secret is an object that allows you to store and manage sensitive information, such as passwords, API keys, and certificates.

For information on building an external issuer, see [Building and Deploying External Issuer For Certificate
Management \[KB1435392\]](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1435392).

## Deployment Requirements {#cert-mngr-integration__section_wbn_sps_dyb}

* Deploy cert-manager in your Kubernetes environment. Update manager.yaml with Instance URL, Certificate Owner Group, Certificate Owner, Environment, and Renewal Tracking.
* Deploy the ServiceNow External Issuer (sn-external-issuer) in your Kubernetes environment. Create a Kubernetes secret clusterissuer-servicenow-credentials with the instance username and password, ensuring the user has the necessary roles to request a certificate.
* The ServiceNow External Issuer supports amd64 architecture along with the latest version of Kubernetes, 1.33.3.
{#cert-mngr-integration__ul_it5_z5d_j1c}

## ServiceNow External Issuer (sn-external-issuer) {#cert-mngr-integration__section_h2s_tps_dyb}

* External issuers expand cert-manager functionality to issue certificates through non-core APIs and services.
* The ServiceNow External Issuer is a ServiceNow-specific implementation of an External Issuer.
* When a new certificate task is created, its Certificate Request UID and Certificate Task Sys Id are stored in the local JSON cache and the Certificate Request UID to Task Map table on the instance.
* The ServiceNow External Issuer polls the instance to monitor the status of the certificate task.
* If the certificate task is in the Work in progress state, its Certificate Request UID and Certificate Task Sys Id are added to the External Issuer UID Map table on the instance and the local JSON cache. During this time, Cert-manager automatically attempts to request the certificate.
* Upon receiving a certificate request, Cert-manager checks for a matching task in the local JSON cache. If found, it polls the same task; otherwise, it queries the instance for records from the External Issuer UID Map table and populates the local JSON cache.
* Once the task is marked as complete and the certificate is generated, the ServiceNow External Issuer sends another request to the instance, downloads the certificate attachment, and updates the certificate resource and corresponding secret in Kubernetes.
{#cert-mngr-integration__ul_tcm_svd_j1c}

## Deploying the ServiceNow External Issuer in Kubernetes {#cert-mngr-integration__section_ksl_vps_dyb}

Deploying the ServiceNow External Issuer in Kubernetes involves the following steps:

1. From the ServiceNow instance download page, obtain the Helm Chart or YAML zip package.
2. Customize the `manager.yaml` or `values.yaml` files as needed for your specific use case. These files may include essential information such as the Instance URL and Certificate Owner Group.
3. Create a Kubernetes secret named `clusterissuer-servicenow-credentials` with the instance username and password.  
   Example command:
   * Create a Kubernetes secret named `clusterissuer-servicenow-credentials` with the instance username and password. Example command:

         kubectl create secret generic clusterissuer-servicenow-credentials
                       --from-literal=user=<user_name> --from-literal=password=<password> -n
                     system

   * Ensure that the user has the necessary roles to request certificates.
   {#cert-mngr-integration__ul_uvs_wxd_j1c}
4. Execute the following commands for deployment.  

       kubectl create ns system
       kubectl apply -f crd
       kubectl apply -f rbac
       kubectl apply -f issuers
       kubectl apply -f manager/manager.yaml

5. (Optional) Customize any additional configurations in the files to suit your specific requirements.
6. Ensure that the deployment is successful and the ServiceNow External Issuer is up and running.
{#cert-mngr-integration__ol_qtb_4wd_j1c}

## Request new certificate flow {#cert-mngr-integration__section_j3g_yps_dyb}

After deployment, submit a certificate resource with the following information in a file named `certificate_clusterissuer.yaml`.

* issuerRef : clusterissuer-servicenow
* issuer : issuer-servicenow
* kind : ClusterIssuer
* issuerRef : servicenow-issuer.servicenow.com

{#cert-mngr-integration__ul_ocs_4xy_fyb}

Here's a sample Certificate Resource:

    apiVersion: cert-manager.io/v1
    kind: Certificate
    metadata:
    name: certificate-by-clusterissuer
    spec:
    commonName: certificate-by-clusterissuer.servicenow.com
    secretName: certificate-by-clusterissuer
    dnsNames:
    - servicenow.com
    - foo.servicenow.com
    issuerRef:
    name: clusterissuer-servicenow
    group: servicenow-issuer.servicenow.com
    kind: ClusterIssuer

Apply the certificate resource using `kubectl apply -f certificate_clusterissuer.yaml`

