Solutions · Cloud-Native

PKI at the speed of your deployments.

Containers scale in seconds, functions live for milliseconds, service meshes require mTLS everywhere. TigerTrust delivers cloud-native certificate management built for microservices, Kubernetes, and serverless — not retrofitted from a corporate CA.

The problem

Legacy PKI wasn't built for workloads that vanish in seconds.

Ticketed cert issuance, human approvals, and 90-day rotations map badly to ephemeral pods and 24-hour SPIFFE IDs. Cloud-native teams either write their own CA glue or ship without mTLS.

Without cloud-native PKI
  • Manual cert requests block CI/CD; developers copy-paste PEMs into secrets
  • Service mesh mTLS breaks when the internal CA can't keep pace with scale events
  • No unified inventory across 200 clusters — expiries surprise you in production
  • Short-lived certificates are impossible with human-in-the-loop issuance
  • GitOps workflows leak long-lived secrets into Git history
With TigerTrust cloud-native PKI
  • Sub-second issuance via ACME, SPIFFE, or Kubernetes CSR API
  • Native cert-manager, Istio, Linkerd, and Consul Connect integrations
  • Central control plane across every cluster, cloud, and region
  • 24-hour or shorter certificate TTLs with fully automated rotation
  • GitOps-friendly CRDs — no long-lived key material in your repos
Kubernetes-native

First-class Kubernetes and cert-manager integration

Ship a Helm chart, install the operator, and every Certificate CRD is fulfilled by TigerTrust. Existing cert-manager workflows keep working — the PKI just gets stronger.

How it works
  • cert-manager ClusterIssuer / Issuer support
  • Native CRDs for policy and lifecycle
  • CSI driver for pod-mounted certificates
  • Helm charts, Kustomize, and OpenShift operators
Kubernetes cluster running cloud-native workloads
Service mesh

mTLS everywhere without breaking a sweat

Act as the trust root for Istio, Linkerd, or Consul Connect. Workload identities minted via SPIFFE/SPIRE, rotated automatically, and revoked in seconds.

How it works
  • SPIFFE/SPIRE compatible workload identities
  • Istio Citadel and Linkerd identity replacement
  • Consul Connect intentions integration
  • Cross-mesh federation for multi-cluster
Service mesh visualization with encrypted traffic flows
Serverless

Certificates for functions that live milliseconds

Issue on invocation, cache in-process, expire on tear-down. AWS Lambda, Azure Functions, and Cloud Run get first-class treatment with sub-100ms overhead.

How it works
  • On-demand issuance via lightweight SDK
  • IMDS-style credential broker
  • Function-scoped trust bundles
  • API Gateway mTLS support
Serverless function fabric with rapid execution
GitOps

Certificates as code, without the risk

Declare policy in Git, apply via ArgoCD or Flux. Nothing sensitive ever lands in a repo — only intent. TigerTrust reconciles state from the outside.

How it works
  • Terraform, Pulumi, Crossplane providers
  • ArgoCD / Flux application sync
  • Policy-as-code with OPA / Kyverno
  • Audit trail every reconcile
GitOps continuous delivery pipeline for cloud-native infrastructure
Cloud-native from day one

Everything modern platforms need. Nothing they don't.

Composable primitives that fit alongside your existing platform stack.

Kubernetes operator
Native CRDs, cert-manager compatibility, CSI driver.
  • Helm chart install
  • Multi-cluster
  • OpenShift ready
Service mesh CA
Trust root for Istio, Linkerd, Consul, SPIFFE.
  • SPIFFE-compatible
  • Cross-mesh federation
  • Workload identity
Automated rotation
Zero-downtime rotation with canary and rollback.
  • Sub-second issuance
  • 24-hour TTLs
  • Health-gated cutover
Fleet control plane
One view across every cluster, region, and cloud.
  • Global inventory
  • Cross-cluster policy
  • Federated audit
Cloud provider hooks
AWS ACM, Azure Key Vault, GCP CAS integration.
  • Native APIs
  • IAM/OIDC auth
  • ELB/ALB provisioning
Observability
Prometheus metrics, OpenTelemetry traces, structured logs.
  • Cert expiry SLIs
  • Issuance latency
  • Grafana dashboards

From cloud-native deployments

<1s
Certificate issuance latency
100K+
Certificates per cluster
24h
Typical SPIFFE TTL supported
99.99%
Rotation success rate
Case study
Hyperscale · SaaS platform

220 clusters, one control plane, zero cert incidents.

We were pinning cert-manager to three different in-cluster CAs. Consolidating to TigerTrust cut our SPIFFE trust bootstrap from a runbook to a Helm value.
Principal Platform Engineer
220
Clusters unified
2.4M
Workload identities
99.99%
Mesh mTLS uptime
Integrations

Fits your existing stack

Composable primitives that fit alongside the CNCF projects your platform already runs on.

Kubernetes
Orchestrator
cert-manager
Controller
Istio
Mesh
Linkerd
Mesh
Consul Connect
Mesh
SPIFFE / SPIRE
Identity
ArgoCD
GitOps
Flux
GitOps
Kyverno
Policy
OPA / Gatekeeper
Policy
Prometheus
Observability
OpenTelemetry
Observability
FAQ

Frequently asked questions

No. TigerTrust ships as a cert-manager ClusterIssuer, so every existing Certificate CRD, Ingress annotation, and Gateway API reference keeps working unchanged. The change your team notices is that renewals succeed faster, inventory is centralised across clusters, and audit logs are consistent. You can keep other issuers alongside TigerTrust for gradual migration.
TigerTrust acts as an upstream trust root for SPIRE (or as a replacement for Istio Citadel / Linkerd identity). Workloads receive short-lived (24h or less) SVIDs bound to attestor claims — Kubernetes ServiceAccount, node identity, or federated OIDC. TTLs, trust domain federation, and cross-cluster SPIFFE bundles are configured through CRDs, so the same GitOps workflow that ships apps ships trust.
The SDK issues on invocation, caches for the function warm window, and drops the private key when the container tears down. Median overhead is under 100ms on cold start, single digit ms warm. API Gateway mTLS termination and function-scoped trust bundles are supported natively. There are no long-lived credentials burned into function environment variables.
One TigerTrust control plane can act as trust root for many meshes and clusters. Federation happens via SPIFFE trust domain bundles that clusters fetch on a schedule. Cross-cluster mTLS works out of the box because the root of trust is common. For multi-region you can pin issuance to a region while replicating policy and inventory globally.
No. All policy — issuers, algorithm allow-lists, TTL bounds, RBAC — lives in CRDs. Nothing sensitive ever lands in Git; only intent. TigerTrust reconciles state from the outside, and the CSI driver mounts material at runtime. ArgoCD and Flux Application syncs work exactly as they do with any other CRD.
PKI Core replicas scale horizontally; a typical 3-node cluster handles well over 100k issuances per hour with sub-second p99 latency. Storage is dominated by audit log retention, not certificate metadata. Customers running 200+ clusters typically operate the control plane on 3–6 nodes plus Postgres and NATS.

Ship faster with mTLS everywhere.