---
title: "Certificate"
description: "a TLS certificate issued inside the cluster by cert-manager and kept as a secret"
section: concepts
address: /concepts/certificate
contract: 0476e35e6e275db5
---

# Certificate

a TLS certificate issued inside the cluster by cert-manager and kept as a secret

[figure: Certificate is a definition at platform scope. The drawing shows its fields and the objects that they point at.]

| property | value |
|---|---|
| kind | definition |
| scope | platform |
| key | the host names it covers |
| store | vault |
| family | network |



## Fields


| field | type | required | note |
|---|---|---|---|
| `hosts` | `[text]` | yes |  |
| `issuer` | `text` | yes |  |
| `not_before` | `time` | yes |  |
| `not_after` | `time` | yes |  |
| `secret` | [VaultEntry](/concepts/vaultentry) | yes | where the key is kept; never on disk in a file |
| `renew_before` | `duration` | yes | the alarm and the renewal fire this long before expiry |



## Routes that use it
No route takes or returns Certificate directly. The record holds it, and the objects that point at it reach it.
