# K8s install how to automate certificate renewal

**URL:** <https://hub.mender.io/t/k8s-install-how-to-automate-certificate-renewal/7597>\
**Category:** General Discussions\
**Tags:** mender-server, kubernetes, tls-certificate\
**Created:** [February 25, 2025, 6:45pm UTC](https://hub.mender.io/t/k8s-install-how-to-automate-certificate-renewal/7597 "2025-02-25T18:45:45Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![neileeyo](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/neileeyo/32/1903_2.png) [@neileeyo](https://hub.mender.io/u/neileeyo)\
**Post date:** [February 25, 2025, 6:45pm UTC](https://hub.mender.io/t/k8s-install-how-to-automate-certificate-renewal/7597/1 "2025-02-25T18:45:45Z")

</div>

I have the mender server installed in AWS in a kubernetes cluster which is working well. The challenge I have is when the cert-manager renews the tls certificate I have to manually update the certificate for the api-gateway. I see there is an option (`api_gateway.certs.existingSecret`) for the helm chart to use an existing secret but the expected keys (`cert.crt` and `private.key`) are different from the cert-manager generated secret (`tls.crt` and `tls.key`). Is it possible to modify the expected keys so that they match the cert-manager secret? That would remove the manual step to update the api-gateway cert as it could reference the cert-manager secret. If not, do you have any recommendations on how to automate the api-gateway cert renewal?

---

<div class="post-metadata">

**Author:** ![robgio](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/robgio/32/1760_2.png) [@robgio](https://hub.mender.io/u/robgio)\
**Post date:** [February 26, 2025, 9:58am UTC](https://hub.mender.io/t/k8s-install-how-to-automate-certificate-renewal/7597/2 "2025-02-26T09:58:50Z")

</div>

Hi @neileeyo ,  
luckily a nice contribution is addressing your need: [Switch api-gateway tls certificate to k8s tls type by chriswiggins · Pull Request #443 · mendersoftware/mender-helm · GitHub](https://github.com/mendersoftware/mender-helm/pull/443)  
I’ll get back to you as soon as this is released

---

<div class="post-metadata">

**Author:** ![neileeyo](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/neileeyo/32/1903_2.png) [@neileeyo](https://hub.mender.io/u/neileeyo)\
**Post date:** [February 26, 2025, 4:39pm UTC](https://hub.mender.io/t/k8s-install-how-to-automate-certificate-renewal/7597/3 "2025-02-26T16:39:12Z")

</div>

Excellent. That’s exactly what I need. Thank you for the follow up @robgio!

---

<div class="post-metadata">

**Author:** ![robgio](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/robgio/32/1760_2.png) [@robgio](https://hub.mender.io/u/robgio)\
**Post date:** [February 26, 2025, 4:41pm UTC](https://hub.mender.io/t/k8s-install-how-to-automate-certificate-renewal/7597/4 "2025-02-26T16:41:34Z")

</div>

Actually, just wait a bit 😉 it turned out to be a breaking change, so we’re reworking it 🙂

---

<div class="post-metadata">

**Author:** ![neileeyo](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/neileeyo/32/1903_2.png) [@neileeyo](https://hub.mender.io/u/neileeyo)\
**Post date:** [February 26, 2025, 5:15pm UTC](https://hub.mender.io/t/k8s-install-how-to-automate-certificate-renewal/7597/5 "2025-02-26T17:15:22Z")

</div>

Any possibility that this change (in it’s non breaking form) could be cherry picked onto [mender-5.12.0](https://github.com/mendersoftware/mender-helm/releases/tag/mender-5.12.0) helm release?

---

<div class="post-metadata">

**Author:** ![robgio](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/robgio/32/1760_2.png) [@robgio](https://hub.mender.io/u/robgio)\
**Post date:** [February 26, 2025, 5:55pm UTC](https://hub.mender.io/t/k8s-install-how-to-automate-certificate-renewal/7597/6 "2025-02-26T17:55:24Z")

</div>

Yes, I think so. The 5.x branch is the default for the still supported Mender Server v3.7

---

<div class="post-metadata">

**Author:** ![robgio](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/robgio/32/1760_2.png) [@robgio](https://hub.mender.io/u/robgio)\
**Post date:** [March 3, 2025, 10:56am UTC](https://hub.mender.io/t/k8s-install-how-to-automate-certificate-renewal/7597/7 "2025-03-03T10:56:00Z")

</div>

Hi @neileeyo , you can try with the new fresh [version 5.13.0](https://github.com/mendersoftware/mender-helm/releases/tag/mender-5.13.0).

---

<div class="post-metadata">

**Author:** ![neileeyo](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/neileeyo/32/1903_2.png) [@neileeyo](https://hub.mender.io/u/neileeyo)\
**Post date:** [March 3, 2025, 4:40pm UTC](https://hub.mender.io/t/k8s-install-how-to-automate-certificate-renewal/7597/8 "2025-03-03T16:40:31Z")

</div>

@robgio that’s great! Thank you for following up. I’ll be testing that today.
