The Red Hat Ecosystem Catalog is the official source for discovering and learning more about the Red Hat Ecosystem of both Red Hat and certified third-party products and services.
We’re the world’s leading provider of enterprise open source solutions—including Linux, cloud, container, and Kubernetes. We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

CyberArk Certificate Manager Operator for Red Hat OpenShift simplifies deployment of Certificate Manager's components like cert-manager
The operator, formerly known as the Venafi Control Plane Operator, simplifies the deployment of enterprise components part of the CyberArk Certificate Manager for Kubernetes.
The components include:
- cert-manager: An enterprise distribution of cert-manager designed for application certificate management within your clusters.
- Enterprise Issuer: Enables seamless certificate enrollment directly from the Certificate Manager.
- Workload Identity Manager: A high-performance issuer for certificates, centrally managed by the Certificate Manager.
- Agent: Provides real-time visibility into cluster resources directly within the Certificate Manager.
The CyberArk Certificate Manager Operator simplifies installation, maintenance, and upgrades of Certificate Manager's components. Leveraging VenafiInstall manifests, it precisely defines your desired deployment state. This operator streamlines the process by providing:
- Deployment Packages: Platform operators can effortlessly select and deploy the necessary components tailored to the needs of their teams.
- Version Compatibility: Each release comes with a set of "default" component versions which are tested together, improving compatibility for users.
- Version Pinning: Specify precise versions of the Certificate Manager's components to ensure consistent deployments across diverse environments.
- Distributed Releases: Effortlessly manage releases across multiple clusters, facilitating complex multi-environment deployments.
- Upgrades: Seamlessly upgrade components, ensuring a smooth transition between versions.
An enterprise distribution of cert-manager designed for application certificate management within your clusters.
Key features:
- Long Term Support (LTS): Enterprise-grade offering built and supported by the expert team that maintains the cert-manager open source project.
- Highest grade compliance: Enhances security and provides FIPS 140-2 compliance for machine identity management.
Enables seamless certificate enrollment for your clusters directly from the CyberArk Certificate Manager for Kubernetes. Enterprise Issuer is a cert-manager issuer that can be either cluster-wide or per namespace.
Lightweight and ephemeral, Workload Identity Manager goes beyond conventional PKI systems, bridging the gap between platform efficiency and security compliance.
By working in tandem with the CyberArk Certificate Manager for Kubernetes, Workload Identity Manager combines centralized governance with decentralized identity issuance, empowering your team to securely validate and authenticate every workload identity, in every environment.
Gain real-time visibility into certificates and other cluster resources directly within the CyberArk Certificate Manager for Kubernetes. The Kubernetes Agent gathers data for machine identities and other cluster resources, such as ingresses, from clusters connected to the CyberArk Certificate Manager for Kubernetes.
Red Hat certified products are tested to meet Red Hat’s criteria and supported as defined in the Red Hat Collaborative Support Process.
Partner validated products are tested by Red Hat Partners and supported as defined in the Red Hat Third Party Component Policy.
Red Hat OpenShift 4.12, 4.14, 4.16, 4.17, 4.18, 4.19, 4.20, 4.21, 4.22
Red Hat OpenShift 4.12, 4.14, 4.16, 4.17, 4.18, 4.19, 4.20, 4.21, 4.22
Yes, a CyberArk Certificate Manager subscription is required to deploy enterprise components for OpenShift using the CyberArk Certificate Manager Operator. These components rely on CyberArk Certificate Manager's functionality to manage machine identities.
Want to try CyberArk Certificate Manager for Kubernetes?
You can sign up for a free trial of CyberArk Certificate Manager for Kubernetes at https://www.cyberark.com/products/certificate-manager-for-kubernetes/.
Contact CyberArk
For more information, contact CyberArk directly at https://www.cyberark.com/talk-with-us/.
CyberArk is a cybersecurity company specializing in privileged access management (PAM) and identity security. It helps organizations protect critical assets by securing privileged accounts, managing identities, and enforcing least-privilege access. It's a leader in Machine Identity Security for securing machine identities.
Scattered, disparate uses of machine identities across the data center, cloud and multi cloud have made it difficult for enterprises to accurately measure their machine identity risk levels. Manual approaches to management are no longer feasible, and enterprises need a new way to control these unprecedented levels of complexity. CyberArk created the Certificate Manager for Machine Identities to provide the highest levels of security and ensure no machine identities fall through the cracks—or between the lines of an outdated spreadsheet or siloed management system.
Venafi was acquired by CyberArk, which means that Venafi’s products and technologies are now part of the CyberArk portfolio. As a result, you may still see "Venafi" in some places, particularly where product names or references to specific technologies exist, but they are now officially part of the CyberArk portfolio.