Feedback Requests
Complete

Phase 8.11 - An internal certificate authority

Internal (non-public) services have relied on ad hoc self-signed certificates with no shared trust anchor — every browser warning clicked through. This phase replaces that with a real, distributable internal certificate authority: a two-tier root/intermediate design where the root key never touches any running system. Phase 1 (the CA itself, live and healthy) is done. Phase 2 (migrating actual internal traffic to it, extending it to non-Kubernetes infrastructure, and automated trust distribution to every machine on the network) is next.

0 Comments

Sign in to comment

No comments yet. Be the first to share your thoughts!