Automatic SSL Certificate Exchange with SwissSign on Kubernetes

05.08.2026 Ueli Scheidegger

The maximum validity period for TLS certificates is gradually being reduced to 47 days. What has long been standard practice at Let’s Encrypt is now becoming mandatory for commercial certificates as well: Our DevOps team demonstrates how SwissSign certificates are renewed fully automatically on Kubernetes.

Anyone who uses Let's Encrypt in Kubernetes is already familiar with automatic certificate renewal: Due to the short certificate validity period of just 90 days, automated renewal has been standard practice for years. Tools like cert-manager ensure that certificates are renewed on time and automatically distributed throughout the cluster. 

 

However, this automation will no longer be relevant only to Let's Encrypt in the future. The CA/Browser Forum standard calls for a gradual reduction in the maximum validity period of publicly trusted TLS certificates. Starting March 15, 2029, the maximum validity period will be reduced to just 47 days. This also affects commercial certificates from providers such as SwissSign. 

SSL

The Challenge

Fliessendes Wasser

While certificates are often renewed once a year today, significantly more frequent renewal cycles will be required in the future. Manual processes not only result in high operational costs but also increase the risk of expired certificates and unexpected service interruptions. 

The Solution

Our DevOps team is therefore integrating SwissSign certificates into an automated Kubernetes process, enabling them to manage the entire certificate lifecycle without manual intervention.

Certificates are renewed in a timely manner through SwissSign.

New certificates are automatically provisioned as Kubernetes Secrets. 

Ingress controllers and applications will adopt the updated certificates. 

The replacement is performed without interrupting operations. 

Advantages & Conclusion

Bergsee

With certificate validity periods set to become significantly shorter in the future, automated certificate management will also become a necessity for SwissSign and other commercial certificates. Automation reduces operational overhead, prevents outages caused by expired certificates, and enhances security through regular certificate rotation. Let’s Encrypt and commercial certificates are managed through a unified process.

Kubernetes offers the ideal platform for this: Certificates are automatically renewed, distributed, and activated—allowing operations teams to focus on their applications rather than on certificate expiration.

Contact our Head of DevOps!

Pascal Zingg Senior DevOps Engineer Contact

Our services in the area of DevOps

Architecture

We support you with your DevOps projects by analysing your existing infrastructure and creating a solution architecture.

Engineering

We build your DevOps infrastructure from the first code commit to productive monitoring.

Platforms

We develop Kubernetes solutions on cloud platforms such as Azure, AWS, GKE or on premise.

Integrations

We integrate your existing services with a modern and reliable DevOps infrastructure.