Automating SSL Certificates on Google Cloud with Certificate as a Service
Nicole BrownShare
Google Cloud treats each SSL Certificate as a resource you create once and then point your services at. It offers two separate places to keep one, and the two behave differently. That difference decides how much work lands on you each time an SSL Certificate is reissued.
Across the industry, those reissues now arrive far more often. The maximum validity of an SSL Certificate has already dropped to 200 days, and it falls again to 100 days and then to 47 days by 2029. Managing that by hand, for every domain, stops being practical. Learn About The Shorter Validity Periods 🔗
Trustico® offers a way to hand that cycle to automation that runs inside your own Google Cloud project. The sections below cover how Google Cloud keeps an SSL Certificate, where the manual effort comes from, and how the Trustico® service removes it.
Two Ways Google Cloud Stores an SSL Certificate
The place an SSL Certificate lives in decides what happens at each reissue. Google Cloud offers two, and knowing the difference explains why automation helps so much.
Certificate Manager
Certificate Manager is the modern store. You create one SSL Certificate object, and every reissue updates that same object in place.
A load balancer reaches the SSL Certificate through a Certificate Map, which matches each hostname to the SSL Certificate it should use. Once the map points at the object, the wiring never changes again, because the object itself is simply refreshed on each reissue.
The Classic Compute Store
The classic Compute store works the other way. Every reissue creates a new, separate SSL Certificate resource instead of updating an existing one, so the resources build up over time until you remove the old ones yourself.
A load balancer keeps serving the previous resource until it is pointed at the new one. So each reissue needs that repointing step before visitors are served the current SSL Certificate.
Where the Manual Work Comes From
Installing an SSL Certificate on Google Cloud once is manageable. You prepare the files, create the resource, and attach it to your load balancer. The trouble is that this is no longer a one-time task.
Every reissue repeats part of it. With the classic Compute store, every reissue also means repointing the load balancer and, in time, clearing out the resources that have piled up. Learn About Installing One by Hand 🔗
Multiply that by the number of domains you run, and by the number of reissues each year, and the schedule alone becomes a liability. One missed reissue is an expired SSL Certificate and a browser warning in front of every visitor.
Automating It in Your Own Google Cloud Project
Trustico® Certificate as a Service (CaaS) for Google Cloud turns the whole cycle into a small job that runs once a day inside your own project. The job obtains your SSL Certificate through the Automatic Certificate Management Environment (ACME) protocol, installs it, and reissues it well before it expires. Nothing is needed from you after setup.
Because the job runs in your project rather than on Trustico® servers, your Private Key is created and kept inside your own Google Cloud project and never leaves it. Trustico® does not hold it. Learn About Google Cloud SSL Certificate Automation 🔗
A Solution in Two Parts
The service is built in two parts. The first does the core work of issuing and installing your SSL Certificate. The second is a set of courtesy scripts that set each Google Cloud store up correctly and keep it working from day to day.
The Automated Job
The job installs your SSL Certificate into Certificate Manager, the classic Compute store, or both at once, so one job can serve whichever Google services read from either store. On each run it checks what is in place, reissues anything that is due, and installs the result.
On a day with nothing due, it confirms that every SSL Certificate is current and finishes in seconds. The reissue happens on its own, long before anything is close to expiring.
The Courtesy Scripts
Setting each store up correctly, and keeping it correct, is where the scripts earn their place. For Certificate Manager, a script makes sure your Certificate Map points at the SSL Certificate the job maintains, then checks each day that it is still in place.
That link is made only once. Because Certificate Manager updates the SSL Certificate in place, the map keeps pointing at the same object and never needs changing when the SSL Certificate is reissued.
The classic Compute store asks more of the scripts, because each reissue is a new resource rather than an in-place update. Here a script checks each day that the setup is still valid and installs each newly reissued SSL Certificate onto the load balancer that uses it.
So the load balancer is always serving the current SSL Certificate, without you touching it. A further script can alert you by e-mail if a run ever fails, so a problem never passes unnoticed.
The Case for Automating It
Automation turns a recurring chore into something that simply runs. The expiry you used to track is handled before it becomes a risk, and the shrinking validity periods stop being your problem to manage.
Changing what the job covers later stays just as light. Adding or removing a domain, or a whole subscription, is an edit to the configuration file you keep, applied once more, and the job takes it from the next run.
One Trustico® Certificate as a Service (CaaS) subscription covers unlimited reissues for your domains, so the cost stays predictable however often the SSL Certificate is reissued. Learn About Certificate as a Service (CaaS) 🔗
Tip : Because the job runs in your own Google Cloud project, your Private Key never leaves it. Trustico® does not store Private Keys, so there is nothing to download, pass around, or lose.
For a single SSL Certificate or for many, the job behaves the same way, so the service grows with you rather than adding work.
Getting Started
Getting started takes two steps. First, choose a Trustico® Certificate as a Service (CaaS) SSL Certificate for the domains you want to secure, which gives you one subscription that covers unlimited reissues. View Our Certificate as a Service (CaaS) SSL Certificates 🔗
Then set up the job once. The guide walks you from an empty project to a running job in about thirty minutes, after which every reissue happens without you. Learn About Setting Up the Google Cloud CaaS Job 🔗
From there the SSL Certificate looks after itself, in the store or stores you chose, for as long as your subscription stays active.