# Usage of AWS Cert Manager

**URL:** <https://discuss.pomerium.com/t/usage-of-aws-cert-manager/337>\
**Category:** Support\
**Tags:** k8s\
**Created:** [February 22, 2024, 9:42am UTC](https://discuss.pomerium.com/t/usage-of-aws-cert-manager/337 "2024-02-22T09:42:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![arun.sisodiya](https://avatars.discourse-cdn.com/v4/letter/a/919ad9/32.png) [@arun.sisodiya](https://discuss.pomerium.com/u/arun.sisodiya)\
**Post date:** [February 22, 2024, 9:42am UTC](https://discuss.pomerium.com/t/usage-of-aws-cert-manager/337/1 "2024-02-22T09:42:25Z")

</div>

## Usage of AWS Cert Manager instead of cert-manager

With the new versions of Pomerium, I have identified that Pomerium is supporting cert-manager for the certificates of Ingress but I want to use the AWS Cert manager for the certificates of Ingress.

Can you help me to understand, how that can be done?

## What did you expect to happen?

## How’d it happen?

1. Ran `x`
2. Clicked `y`
3. Saw error `z`

## What’s your environment like?

- Pomerium version (retrieve with `pomerium --version`): v0.23
- Server Operating System/Architecture/Cloud: AWS EKS

## What’s your config.yaml?

```auto
# Paste your configs here
# Be sure to scrub any sensitive values

```

## What did you see in the logs?

```logs
# Paste your logs here.
# Be sure to scrub any sensitive values

```

## Additional context

Add any other context about the problem here.

---

<div class="post-metadata">

**Author:** ![denis](https://avatars.discourse-cdn.com/v4/letter/d/5e9695/32.png) [@denis](https://discuss.pomerium.com/u/denis)\
**Post date:** [February 22, 2024, 3:20pm UTC](https://discuss.pomerium.com/t/usage-of-aws-cert-manager/337/2 "2024-02-22T15:20:35Z")

</div>

Pomerium Ingress Controller just [watches certificates](https://www.pomerium.com/docs/deploy/k8s/ingress#tls-certificates) that are stored in secrets, and is generally agnostic to where the certificates are originating from.

while I personally not familiar with AWS Cert Manager, it seems to have an official integration with `cert-manager`: [TLS-enabled Kubernetes clusters with ACM Private CA and Amazon EKS | AWS Security Blog](https://aws.amazon.com/blogs/security/tls-enabled-kubernetes-clusters-with-acm-private-ca-and-amazon-eks-2/)
