Home/Certificate Management
Section 8 of 1942% complete

Section 8: Certificate Management

TLS Strategy

All communications encrypted with TLS. Different certificate sources for different tiers.

Tier Certificate Source Rotation
Public endpointsCloudflare (edge)Automatic
Control plane internalcert-manager + Let's Encrypt90 days auto-renew
Agent mTLSInternal CA (planned)24-48 hours
Database connectionsSelf-signed (internal only)Annual

Agent Certificate Lifecycle

  1. 1. Agent enrolls with one-time bootstrap token
  2. 2. Control plane issues short-lived certificate (24-48h)
  3. 3. Agent auto-renews before expiry
  4. 4. Revocation via CRL or real-time check

Key Storage

Private keys never leave their origin. Agent keys generated on-device, control plane keys in Kubernetes secrets.