# cert-manager Public ACME issuers and an internal certificate authority. This directory contains chart values and issuer resources, not the controller installation. Install the cert-manager chart with CRDs and the settings in `k8s/cert-manager-values.yaml` before applying the issuers. `clusterissuer.yaml` defines staging and production Let's Encrypt issuers. They use HTTP-01 through the Traefik ingress class. Public DNS and inbound HTTP reachability must work for the requested names before issuance. `internal-ca.yaml` bootstraps the internal CA. Keep its private-key Secret backed up; the tracked `.crt` is only a public certificate. This directory has no `k8s/active` marker. Apply the issuer files deliberately; `kubectl apply` does not interpret the Helm values file. See the [repository README](../README.md) for deployment selection.