DNScale cert-manager webhook source is now available
Automate Kubernetes DNS-01 certificate validation with DNScale. The webhook source, Helm chart, and staging examples are now public, with installation from source.
The DNScale cert-manager webhook is now available on GitHub with its source code, Dockerfile, Helm chart, and staging examples. Kubernetes teams can use it to automate ACME DNS-01 validation for certificates whose DNS zones are hosted on DNScale.
Installation currently uses a source build. Build the container image in a registry your cluster can access, then install the Helm chart from the repository. A public GHCR image and OCI chart are not yet published. The setup guide covers that installation path.
Certificate validation inside Kubernetes
With the webhook installed, a Certificate resource starts the familiar
cert-manager workflow. cert-manager asks the webhook to publish the temporary
_acme-challenge TXT value through the DNScale API, waits for validation, and
stores the issued certificate in a Kubernetes Secret. The webhook removes the
challenge value when cert-manager requests cleanup.
DNS-01 supports wildcard certificates such as *.example.com and lets you
validate certificates for services that cannot receive public HTTP validation
traffic. The validation zone still needs working public DNS delegation.
You can configure the solver in a namespaced Issuer or a ClusterIssuer.
Use group name acme.dnscale.eu and solver name dnscale; the guide includes
complete staging and production issuer examples.
Keep challenge permissions focused
Store the DNScale token in a Kubernetes Secret and grant it zones:read,
records:read, and records:write for the validation zone. DNScale's DNS-name
scoping lets you restrict it further to the exact challenge owners you need:
_acme-challenge for an apex or wildcard, or _acme-challenge.app for
app.example.com.
The chart grants the webhook read access to explicitly named Secrets. The
setup guide
explains Secret placement and the extra chart configuration for an Issuer
in another namespace.
More than one certificate can use the same challenge record name. The webhook removes only the TXT value belonging to the completed challenge, preserving other values at that name. Repeated presentation and cleanup are covered by the repository's tests and live API verification script.
Verified with Let's Encrypt staging
We verified apex and wildcard issuance, a manually triggered renewal, and challenge TXT cleanup against the live DNScale API and Let's Encrypt staging using Kubernetes 1.35.0 and cert-manager 1.19.3. Those are the tested versions; validate the integration in your own cluster before using a production issuer.
The repository's CI also checks the Go solver, builds the container, installs the chart in Kubernetes, and verifies webhook readiness and Secret access. The staging flow in the guide lets you check public DNS propagation and certificate issuance with your own domain.
Follow the cert-manager setup guide, read the changelog entry, or browse the source and issue tracker.
Managed authoritative DNS
Run DNS with observability built in
Start free, then move to Scale or custom plans when you need DNS traffic alerts, higher query volume, and dedicated human support.