Signed certs for internal services (internal CA with step-ca) #31

Open
opened 2026-08-19 02:25:37 +00:00 by itguyeric · 0 comments
Owner

Get real TLS on internal-only services (Proxmox, OPNsense, cockpit on bast, anything on .int.itguyeric.com) instead of self-signed warnings. Stand up an internal ACME CA with step-ca, distribute the root to the fleet and workstations, and let internal services request and renew certs automatically.

Pairs with the split-DNS .int names already in use. Pets like Proxmox and OPNsense get certs installed by hand or via Ansible; bootc hosts can trust the root at build time.

Get real TLS on internal-only services (Proxmox, OPNsense, cockpit on bast, anything on `.int.itguyeric.com`) instead of self-signed warnings. Stand up an internal ACME CA with step-ca, distribute the root to the fleet and workstations, and let internal services request and renew certs automatically. Pairs with the split-DNS `.int` names already in use. Pets like Proxmox and OPNsense get certs installed by hand or via Ansible; bootc hosts can trust the root at build time.
itguyeric added this to the Homelab project 2026-08-19 02:25:37 +00:00
Sign in to join this conversation.
No description provided.