Internal certificate authority for admin tools
Admin-facing infrastructure tools (deployment dashboards, storage UIs, monitoring, automation consoles) used independent, ad hoc self-signed certificates with no shared trust anchor, so every browser warned on every visit.
A single internal certificate authority now issues trusted TLS certificates for these tools instead, with a two-tier setup: an offline root that never touches any running system, and an online intermediate that does the day-to-day signing. If the intermediate is ever compromised, it can be reissued without redistributing a new root everywhere.
Every internal admin tool ingress across both clusters has been switched over. Certificates for internal service-to-service connections (not browser-facing) are a separate, later piece of work.
0 Comments
Sign in to comment
No comments yet. Be the first to share your thoughts!
