cert-manager-acmesolver
Secure by Design, Built for Speed, Hardened Container Images on a minimal base CleanStart OS.
50K+
ACME solver component for cert-manager, designed for automated certificate management and validation in enterprise Kubernetes environments. Provides secure, compliant certificate challenge resolution.
š Base Foundation: Security-hardened, minimal base OS designed for enterprise containerized environments from Cleanstart Registry.
Image Path: cleanstart/cert-manager-acmesolver
Registry: Cleanstart Registry
Key Features Core capabilities and strengths of this container
Common Use Cases Typical scenarios where this container excels
Pull Latest Image Download the container image from the registry
docker pull cleanstart/cert-manager-acmesolver:latest
docker pull cleanstart/cert-manager-acmesolver:latest-dev
Basic Run Run the container with basic configuration
docker run -it --name cert-manager-acmesolver -test cleanstart/cert-manager-acmesolver:latest-dev
Production Deployment Deploy with production security settings
docker run -d --name cert-manager-acmesolver -prod \
--read-only \
--security-opt=no-new-privileges \
--user 1000:1000 \
cleanstart/cert-manager-acmesolver:latest
Volume Mount Mount local directory for persistent data
docker run -v $(pwd)/challenges:/challenges cleanstart/cert-manager-acmesolver:latest
Port Forwarding Run with custom port mappings
docker run -p 8089:8089 cleanstart/cert-manager-acmesolver:latest
Environment Variables Configuration options available through environment variables
| Variable | Default | Description |
|---|---|---|
| ACME_CHALLENGE_TYPE | http-01 | Type of ACME challenge to solve |
| ACME_TOKEN | Token for ACME challenge validation | |
| ACME_KEY | Key for ACME challenge response | |
| DEBUG | false | Enable debug logging |
Security Best Practices Recommended security configurations and practices
Kubernetes Security Context Recommended security context for Kubernetes deployments
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
seccompProfile:
type: RuntimeDefault
Essential links and resources for further information:
CleanStart offers Docker images that include third-party open-source libraries and packages maintained by independent contributors. While CleanStart maintains these images and applies industry-standard security practices, it cannot guarantee the security or integrity of upstream components beyond its control.
Users acknowledge and agree that open-source software may contain undiscovered vulnerabilities or introduce new risks through updates. CleanStart shall not be liable for security issues originating from third-party libraries, including but not limited to zero-day exploits, supply chain attacks, or contributor-introduced risks.
Security remains a shared responsibility: CleanStart provides updated images and guidance where possible, while users are responsible for evaluating deployments and implementing appropriate controls.
Content type
Image
Digest
sha256:1c75ac1e9ā¦
Size
26.6 MB
Last updated
about 17 hours ago
docker pull cleanstart/cert-manager-acmesolver:1.21.0-arm64