The Kubernetes Service CA controller issues certificates for Services labelled with service.syn.tools/serving-cert-secret-name.
The controller uses [cert-manager] for the actual certificate issuing and copies the generated certificate secret into the service namespace.