Signed certs for internal services (internal CA with step-ca) #31
Labels
No labels
area/ci
area/media
area/network
area/observability
area/platform
area/security
area/storage
area/web
type/project
type/task
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
itguyeric/infra#31
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Get real TLS on internal-only services (Proxmox, OPNsense, cockpit on bast, anything on
.int.itguyeric.com) instead of self-signed warnings. Stand up an internal ACME CA with step-ca, distribute the root to the fleet and workstations, and let internal services request and renew certs automatically.Pairs with the split-DNS
.intnames already in use. Pets like Proxmox and OPNsense get certs installed by hand or via Ansible; bootc hosts can trust the root at build time.