Certificate Management
This guide covers the recurring work a running Axual Platform needs from its certificates: reading what one currently holds, replacing it before it expires, and moving the whole platform onto a new root Certificate Authority. Getting certificates in place for the first time is a different subject, covered in Certificates, TLS and DNS.
Type |
Reference |
Goal |
Find the certificate task you need on a platform that is already installed. |
Audience |
Platform Operators and infrastructure engineers who read, renew or replace the platform’s certificates. |
When to use |
Whenever a certificate needs reading, is approaching expiry, or an authority is being replaced. Not part of a new installation. |
Installing cert-manager and Reloader removes most of this work, because between them they reissue a certificate and restart the pod that holds it. The pages below cover what is left: the manual path for either tool, and the two jobs neither tool does at all.
Contents
The sections below cover each task in this guide:
-
How to Inspect a Certificate covers reading a certificate from a file, a live endpoint or a cert-manager
Certificate, and listing what is close to expiring. -
How to Rotate a Certificate covers replacing a single certificate, both cert-manager issued and manually managed.
-
How to Replace the Root Certificate Authority covers the two-pass migration that moves every component and client application onto a new authority.
Related pages
-
Certificates, TLS and DNS covers getting certificates in place before an installation, the Secret formats the charts read, and how to point a component at them.
-
Troubleshooting covers what to check when a component fails to start or a connection is refused.