Ingress TLS, mTLS between pods, service-mesh identities, ephemeral job credentials — all managed with cert-manager compatibility, CSI-driver mounts, and CRDs that fit your GitOps workflow.
Every K8s cluster grows a cert-manager install pointed at a Let's Encrypt or self-signed CA. That works until compliance shows up asking about your root, your audit trail, and how you rotate across 200 clusters.
Point your existing cert-manager Certificate resources at TigerTrust. Every workflow — Ingress annotations, Gateway API references, Helm chart values — keeps working with a stronger CA behind them.

Pods mount certificates from the TigerTrust CSI volume like any other filesystem. Rotation happens under the pod without a restart. Zero application changes.

Replace the default mesh CA with a TigerTrust root. Every workload identity — including cross-cluster and cross-mesh — flows through one auditable authority.

Manage 200 clusters like they were one. Central policy, per-cluster tenants, global inventory, and audit that spans regions.

Every piece designed for the CNCF stack — CRDs, controllers, CSI, RBAC, all first-class.
From Kubernetes deployments
“Every cluster we spin up joins the trust root automatically. cert-manager Certificate CRDs just work — the platform team stopped being the CA team.”
Every Kubernetes distribution, mesh, and GitOps tool the CNCF stack ships with.
The cert-manager and CSI implementation in detail.
SPIFFE workload identity and API-first primitives.
CI/CD plugins and Terraform providers for platform teams.
One control plane across EKS, AKS, GKE, and on-prem.