Automating SSL Certificates on Google Cloud with Certificate as a Service

Automating SSL Certificates on Google Cloud with Certificate as a Service

Nicole Brown

Google Cloud treats each SSL Certificate as a resource you create once and then point your services at. It offers two separate places to keep one, and the two behave differently. That difference decides how much work lands on you each time an SSL Certificate is reissued.

Across the industry, those reissues now arrive far more often. The maximum validity of an SSL Certificate has already dropped to 200 days, and it falls again to 100 days and then to 47 days by 2029. Managing that by hand, for every domain, stops being practical. Learn About The Shorter Validity Periods 🔗

Trustico® offers a way to hand that cycle to automation that runs inside your own Google Cloud project. The sections below cover how Google Cloud keeps an SSL Certificate, where the manual effort comes from, and how the Trustico® service removes it.

Two Ways Google Cloud Stores an SSL Certificate

The place an SSL Certificate lives in decides what happens at each reissue. Google Cloud offers two, and knowing the difference explains why automation helps so much.

Certificate Manager

Certificate Manager is the modern store. You create one SSL Certificate object, and every reissue updates that same object in place.

A load balancer reaches the SSL Certificate through a Certificate Map, which matches each hostname to the SSL Certificate it should use. Once the map points at the object, the wiring never changes again, because the object itself is simply refreshed on each reissue.

The Classic Compute Store

The classic Compute store works the other way. Every reissue creates a new, separate SSL Certificate resource instead of updating an existing one, so the resources build up over time until you remove the old ones yourself.

A load balancer keeps serving the previous resource until it is pointed at the new one. So each reissue needs that repointing step before visitors are served the current SSL Certificate.

Where the Manual Work Comes From

Installing an SSL Certificate on Google Cloud once is manageable. You prepare the files, create the resource, and attach it to your load balancer. The trouble is that this is no longer a one-time task.

Every reissue repeats part of it. With the classic Compute store, every reissue also means repointing the load balancer and, in time, clearing out the resources that have piled up. Learn About Installing One by Hand 🔗

Multiply that by the number of domains you run, and by the number of reissues each year, and the schedule alone becomes a liability. One missed reissue is an expired SSL Certificate and a browser warning in front of every visitor.

Automating It in Your Own Google Cloud Project

Trustico® Certificate as a Service (CaaS) for Google Cloud turns the whole cycle into a small job that runs once a day inside your own project. The job obtains your SSL Certificate through the Automatic Certificate Management Environment (ACME) protocol, installs it, and reissues it well before it expires. Nothing is needed from you after setup.

Because the job runs in your project rather than on Trustico® servers, your Private Key is created and kept inside your own Google Cloud project and never leaves it. Trustico® does not hold it. Learn About Google Cloud SSL Certificate Automation 🔗

A Solution in Two Parts

The service is built in two parts. The first does the core work of issuing and installing your SSL Certificate. The second is a set of courtesy scripts that set each Google Cloud store up correctly and keep it working from day to day.

The Automated Job

The job installs your SSL Certificate into Certificate Manager, the classic Compute store, or both at once, so one job can serve whichever Google services read from either store. On each run it checks what is in place, reissues anything that is due, and installs the result.

On a day with nothing due, it confirms that every SSL Certificate is current and finishes in seconds. The reissue happens on its own, long before anything is close to expiring.

The Courtesy Scripts

Setting each store up correctly, and keeping it correct, is where the scripts earn their place. For Certificate Manager, a script makes sure your Certificate Map points at the SSL Certificate the job maintains, then checks each day that it is still in place.

That link is made only once. Because Certificate Manager updates the SSL Certificate in place, the map keeps pointing at the same object and never needs changing when the SSL Certificate is reissued.

The classic Compute store asks more of the scripts, because each reissue is a new resource rather than an in-place update. Here a script checks each day that the setup is still valid and installs each newly reissued SSL Certificate onto the load balancer that uses it.

So the load balancer is always serving the current SSL Certificate, without you touching it. A further script can alert you by e-mail if a run ever fails, so a problem never passes unnoticed.

The Case for Automating It

Automation turns a recurring chore into something that simply runs. The expiry you used to track is handled before it becomes a risk, and the shrinking validity periods stop being your problem to manage.

Changing what the job covers later stays just as light. Adding or removing a domain, or a whole subscription, is an edit to the configuration file you keep, applied once more, and the job takes it from the next run.

One Trustico® Certificate as a Service (CaaS) subscription covers unlimited reissues for your domains, so the cost stays predictable however often the SSL Certificate is reissued. Learn About Certificate as a Service (CaaS) 🔗

Tip : Because the job runs in your own Google Cloud project, your Private Key never leaves it. Trustico® does not store Private Keys, so there is nothing to download, pass around, or lose.

For a single SSL Certificate or for many, the job behaves the same way, so the service grows with you rather than adding work.

Getting Started

Getting started takes two steps. First, choose a Trustico® Certificate as a Service (CaaS) SSL Certificate for the domains you want to secure, which gives you one subscription that covers unlimited reissues. View Our Certificate as a Service (CaaS) SSL Certificates 🔗

Then set up the job once. The guide walks you from an empty project to a running job in about thirty minutes, after which every reissue happens without you. Learn About Setting Up the Google Cloud CaaS Job 🔗

From there the SSL Certificate looks after itself, in the store or stores you chose, for as long as your subscription stays active.

Back to Blog

Most Popular Questions

Frequently asked questions covering Trustico® Certificate as a Service (CaaS) for Google Cloud, the two Certificate stores, keeping Private Keys in your project, the courtesy scripts, and buying an SSL Certificate

Google Cloud SSL Certificate Automation

Trustico® Certificate as a Service (CaaS) for Google Cloud runs a small daily job inside your own Google Cloud project. It issues your SSL Certificate, installs it, and reissues it before expiry, with no manual step after setup.

Certificate Manager and the Classic Compute Store

Certificate Manager keeps one SSL Certificate object and updates it in place, so a Certificate Map set up once keeps working. The classic Compute store creates a new resource at each reissue, so the load balancer must be pointed at the new SSL Certificate each time.

Keeping Private Keys Inside Your Project

The job runs in your own Google Cloud project, so every Private Key is created and kept there and never leaves it. Trustico® does not store Private Keys, so there is nothing to download or pass around.

The Courtesy Scripts for Each Store

The optional scripts set up each Google Cloud store correctly and keep it working. For Certificate Manager they confirm the Certificate Map still points at the maintained SSL Certificate, and for the classic Compute store they install each reissued SSL Certificate onto the load balancer that uses it.

Buying a Certificate as a Service SSL Certificate

Choose a Trustico® Certificate as a Service (CaaS) SSL Certificate for the domains you want to secure. One subscription covers unlimited reissues, and the same credentials drive the Google Cloud job and any other method you use.

Stay Updated - Our RSS Feed

There's never a reason to miss a post! Subscribe to our Atom/RSS feed and get instant notifications when we publish new articles about SSL Certificates, security updates, and news. Use your favorite RSS reader or news aggregator.

Subscribe via RSS/Atom