This may well have been done to death but I’d not used an automated approach to generating certs for Kubernetes Services and cert-manager acknowledges that its documentation needs refinement: https://cert-manager.readthedocs.io/en/latest/tutorials/acme/dns-validation.html I happened upon Ross Kukulinski’s post “Let’s Encrypt Kubernetes” but the long-promised “Part 2” using Let’s Encrypt has not be