This invention relates to the field of cloud-native gateways and service meshes, and discloses a
route-aware multi-tenant
certificate management method and
system, comprising: upon receiving a tenant
domain name creation request, creating a custom resource for the tenant
domain name and initializing it; when the tenant
domain name controller listens for the creation event of the custom resource for the tenant domain name, reading the Layer 7 routing resource template from the routing template cache, reading the subdomain prefix, and concatenating the subdomain prefix with the tenant's
base domain name to generate a derived subdomain; aggregating all derived subdomains into a multi-domain
certificate and submitting it to the
certificate issuance controller; when the gateway proxy initiates an incremental discovery request to the key discovery and distribution service during the TLS
handshake phase, sequentially querying the local cache, certificate index, and routing template cache, and executing the
handshake admission control steps. This invention solves the problems of write conflicts and consistency issues,
low resource utilization, and long fault
recovery time in scenarios with tens of thousands of domain names.