cleanstart/cert-manager-acmesolver

Verified Publisher

By CleanStart

•Updated about 17 hours ago

Secure by Design, Built for Speed, Hardened Container Images on a minimal base CleanStart OS.

Image
Web servers
0

50K+

cleanstart/cert-manager-acmesolver repository overview

ACME solver component for cert-manager, designed for automated certificate management and validation in enterprise Kubernetes environments. Provides secure, compliant certificate challenge resolution.

šŸ“Œ Base Foundation: Security-hardened, minimal base OS designed for enterprise containerized environments from Cleanstart Registry.

Image Path: cleanstart/cert-manager-acmesolver Registry: Cleanstart Registry

Key Features Core capabilities and strengths of this container

  • Automated ACME challenge resolution
  • Kubernetes-native certificate management
  • Enterprise-grade security compliance

Common Use Cases Typical scenarios where this container excels

  • Automated SSL/TLS certificate management
  • Enterprise Kubernetes certificate orchestration
  • Secure DNS challenge resolution

Pull Latest Image Download the container image from the registry

docker pull cleanstart/cert-manager-acmesolver:latest
docker pull cleanstart/cert-manager-acmesolver:latest-dev

Basic Run Run the container with basic configuration

docker run -it --name cert-manager-acmesolver -test cleanstart/cert-manager-acmesolver:latest-dev

Production Deployment Deploy with production security settings

docker run -d --name cert-manager-acmesolver  -prod \
  --read-only \
  --security-opt=no-new-privileges \
  --user 1000:1000 \
  cleanstart/cert-manager-acmesolver:latest

Volume Mount Mount local directory for persistent data

docker run -v $(pwd)/challenges:/challenges cleanstart/cert-manager-acmesolver:latest

Port Forwarding Run with custom port mappings

docker run -p 8089:8089 cleanstart/cert-manager-acmesolver:latest

Environment Variables Configuration options available through environment variables

VariableDefaultDescription
ACME_CHALLENGE_TYPEhttp-01Type of ACME challenge to solve
ACME_TOKENToken for ACME challenge validation
ACME_KEYKey for ACME challenge response
DEBUGfalseEnable debug logging

Security Best Practices Recommended security configurations and practices

  • Use specific image tags for production deployments
  • Implement proper network policies for challenge endpoints
  • Regular security scanning of container images
  • Monitor certificate lifecycle and renewal processes
  • Implement proper access controls for certificate storage
  • Use secure communication channels for ACME challenges
  • Regular audit of certificate management processes

Kubernetes Security Context Recommended security context for Kubernetes deployments

securityContext:
  runAsNonRoot: true
  runAsUser: 1000
  runAsGroup: 1000
  readOnlyRootFilesystem: true
  allowPrivilegeEscalation: false
  capabilities:
    drop: ["ALL"]
  seccompProfile:
    type: RuntimeDefault

⁠Documentation Resources

Essential links and resources for further information:

⁠Vulnerability Disclaimer

CleanStart offers Docker images that include third-party open-source libraries and packages maintained by independent contributors. While CleanStart maintains these images and applies industry-standard security practices, it cannot guarantee the security or integrity of upstream components beyond its control.

Users acknowledge and agree that open-source software may contain undiscovered vulnerabilities or introduce new risks through updates. CleanStart shall not be liable for security issues originating from third-party libraries, including but not limited to zero-day exploits, supply chain attacks, or contributor-introduced risks.

Security remains a shared responsibility: CleanStart provides updated images and guidance where possible, while users are responsible for evaluating deployments and implementing appropriate controls.

Tag summary

Content type

Image

Digest

sha256:1c75ac1e9…

Size

26.6 MB

Last updated

about 17 hours ago

docker pull cleanstart/cert-manager-acmesolver:1.21.0-arm64