Email for your domain, with DNS setup handled. PostScale

    Sign Up
    Product Updates

    DNScale cert-manager webhook source is now available

    Automate Kubernetes DNS-01 certificate validation with DNScale. The webhook source, Helm chart, and staging examples are now public, with installation from source.

    The DNScale cert-manager webhook is now available on GitHub with its source code, Dockerfile, Helm chart, and staging examples. Kubernetes teams can use it to automate ACME DNS-01 validation for certificates whose DNS zones are hosted on DNScale.

    Installation currently uses a source build. Build the container image in a registry your cluster can access, then install the Helm chart from the repository. A public GHCR image and OCI chart are not yet published. The setup guide covers that installation path.

    Certificate validation inside Kubernetes

    With the webhook installed, a Certificate resource starts the familiar cert-manager workflow. cert-manager asks the webhook to publish the temporary _acme-challenge TXT value through the DNScale API, waits for validation, and stores the issued certificate in a Kubernetes Secret. The webhook removes the challenge value when cert-manager requests cleanup.

    DNS-01 supports wildcard certificates such as *.example.com and lets you validate certificates for services that cannot receive public HTTP validation traffic. The validation zone still needs working public DNS delegation.

    You can configure the solver in a namespaced Issuer or a ClusterIssuer. Use group name acme.dnscale.eu and solver name dnscale; the guide includes complete staging and production issuer examples.

    Keep challenge permissions focused

    Store the DNScale token in a Kubernetes Secret and grant it zones:read, records:read, and records:write for the validation zone. DNScale's DNS-name scoping lets you restrict it further to the exact challenge owners you need: _acme-challenge for an apex or wildcard, or _acme-challenge.app for app.example.com.

    The chart grants the webhook read access to explicitly named Secrets. The setup guide explains Secret placement and the extra chart configuration for an Issuer in another namespace.

    More than one certificate can use the same challenge record name. The webhook removes only the TXT value belonging to the completed challenge, preserving other values at that name. Repeated presentation and cleanup are covered by the repository's tests and live API verification script.

    Verified with Let's Encrypt staging

    We verified apex and wildcard issuance, a manually triggered renewal, and challenge TXT cleanup against the live DNScale API and Let's Encrypt staging using Kubernetes 1.35.0 and cert-manager 1.19.3. Those are the tested versions; validate the integration in your own cluster before using a production issuer.

    The repository's CI also checks the Go solver, builds the container, installs the chart in Kubernetes, and verifies webhook readiness and Secret access. The staging flow in the guide lets you check public DNS propagation and certificate issuance with your own domain.

    Follow the cert-manager setup guide, read the changelog entry, or browse the source and issue tracker.

    Managed authoritative DNS

    Run DNS with observability built in

    Start free, then move to Scale or custom plans when you need DNS traffic alerts, higher query volume, and dedicated human support.

    More from Product Updates