Managed TLS Certificates across clouds

Public certificates the platform issues and renews - ACM, Certificate Manager, Akamai CPS - validated by DNS records the module writes.

3 verified modules, 2 of them live-tested apply→verify→destroy; the rest are static-validated, live-test pending.

Compare by provider

ProviderModuleVerification
AkamaiAkamai CPS DV Certificatestatic-validated
AWSACM Certificate (DNS-validated)✓ live-tested
Google CloudCertificate Manager (certificate map)✓ live-tested

How to choose

Compare validation (DNS validation renews without a person; email validation does not), where the certificate can be attached (a load balancer in the same region, an edge network, anywhere), and whether renewal is automatic or an alert you must answer.

When not to use

A managed certificate is bound to the platform that issued it. The private key never leaves; that is the point, and it also means the certificate cannot be moved to a server elsewhere.

Other solutions